Bug 781460 - [RBAC] manipulating URL allows access to systems in environments w/o permissions
Summary: [RBAC] manipulating URL allows access to systems in environments w/o permissions
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: WebUI
Version: 6.0.0
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: Unspecified
Assignee: Partha Aji
QA Contact: Katello QA List
URL:
Whiteboard:
Depends On:
Blocks: katello-blockers
TreeView+ depends on / blocked
 
Reported: 2012-01-13 14:24 UTC by Tom McKay
Modified: 2019-09-26 13:28 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-08-22 18:19:30 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Tom McKay 2012-01-13 14:24:11 UTC
After creating a role for "Read System in Environment, PRODUCTION" and assigning that role to a new user, login as that user. Visiting Systems By Environment page shows the env selector with only PRODUCTION clickable which is correct. Note the URL in the browser, though, and change the trailing env_id param to another number. Reload the page: Systems in the new env_id are displayed (though the env selector still is locked to PRODUCTION).

Comment 2 Mike McCune 2012-01-26 19:08:23 UTC
mass ON_QA move

Comment 4 Og Maciel 2012-02-13 18:30:32 UTC
Verified on:
* candlepin-0.5.18-1.el6.noarch
* candlepin-tomcat6-0.5.18-1.el6.noarch
* katello-0.1.229-2.el6.noarch
* katello-all-0.1.229-2.el6.noarch
* katello-certs-tools-1.0.2-2.el6.noarch
* katello-cli-0.1.44-2.el6.noarch
* katello-cli-common-0.1.44-2.el6.noarch
* katello-common-0.1.229-2.el6.noarch
* katello-configure-0.1.61-2.el6.noarch
* katello-glue-candlepin-0.1.229-2.el6.noarch
* katello-glue-foreman-0.1.229-2.el6.noarch
* katello-glue-pulp-0.1.229-2.el6.noarch
* katello-httpd-ssl-key-pair-1.0-1.noarch
* katello-qpid-broker-key-pair-1.0-1.noarch
* katello-repos-0.1.5-1.el6.noarch
* katello-selinux-0.1.3-1.el6.noarch
* katello-trusted-ssl-cert-1.0-1.noarch
* pulp-0.0.265-1.el6.noarch
* pulp-common-0.0.265-1.el6.noarch
* pulp-selinux-server-0.0.265-1.el6.noarch


Note You need to log in before you can comment on or make changes to this bug.