Bug 796047
| Summary: | SecurityViolation error while accessing gpg key details with read only user | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Satellite | Reporter: | Sachin Ghai <sghai> | ||||||||
| Component: | WebUI | Assignee: | Partha Aji <paji> | ||||||||
| Status: | CLOSED ERRATA | QA Contact: | Sachin Ghai <sghai> | ||||||||
| Severity: | medium | Docs Contact: | |||||||||
| Priority: | high | ||||||||||
| Version: | 6.0.0 | CC: | achan, asettle, inecas, jlaska, mmccune, omaciel, ppokorny | ||||||||
| Target Milestone: | Unspecified | Keywords: | Triaged | ||||||||
| Target Release: | Unused | ||||||||||
| Hardware: | Unspecified | ||||||||||
| OS: | Unspecified | ||||||||||
| Whiteboard: | |||||||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||||||
| Doc Text: |
When a read-only user attempted to view a GPG key in the graphical user interface, the body of the key was left blank. This was caused by a security violation error where the code had attempted to grant the user edit instead of read permissions. This is fixed in the current version. Users with read-only permission can now view GPG keys.
|
Story Points: | --- | ||||||||
| Clone Of: | Environment: | ||||||||||
| Last Closed: | 2012-12-04 19:42:17 UTC | Type: | --- | ||||||||
| Regression: | --- | Mount Type: | --- | ||||||||
| Documentation: | --- | CRM: | |||||||||
| Verified Versions: | Category: | --- | |||||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||||
| Embargoed: | |||||||||||
| Attachments: |
|
||||||||||
|
Description
Sachin Ghai
2012-02-22 07:23:55 UTC
Created attachment 564851 [details]
Complete error log from production.log
Created attachment 564852 [details]
no details displayed on UI for gpg_keys using read only user
It was fixed long time ago in f61c2db I tested it in Katello Version: 1.1.9-1.git.95.0ed1e6f.el6. Verified with following CFSE build: katello-glue-candlepin-1.1.12-12.el6cf.noarch katello-qpid-client-key-pair-1.0-1.noarch katello-all-1.1.12-12.el6cf.noarch katello-cli-1.1.8-6.el6cf.noarch katello-certs-tools-1.1.8-1.el6cf.noarch katello-selinux-1.1.1-1.el6cf.noarch katello-configure-1.1.9-6.el6cf.noarch katello-candlepin-cert-key-pair-1.0-1.noarch katello-cli-common-1.1.8-6.el6cf.noarch katello-common-1.1.12-12.el6cf.noarch katello-1.1.12-12.el6cf.noarch katello-qpid-broker-key-pair-1.0-1.noarch katello-glue-pulp-1.1.12-12.el6cf.noarch I can see the created gpg_key details using read only user and no error generated under production.log. Created attachment 620677 [details]
can see details of gpg-key using read only user
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2012-1543.html |