Project

General

Profile

Bug #36272

Read-only user should not see "Purge Trash" action

Added by Ricardo Marques about 4 years ago. Updated over 1 year ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Component - RBD
Target version:
-
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

After login with a read-only user, I'm able to see an action that should require "delete" permissions:

s1.png View (8.55 KB) Ricardo Marques, 10/01/2018 04:49 PM

History

#1 Updated by Volker Theile about 4 years ago

We should add unit tests for those scenarious to make sure that this does not happen. Hardening the WebUI and make sure a user is not allowed to do actions with higher privileges is really important nowadays.

#2 Updated by Tiago Melo about 4 years ago

  • Status changed from New to Fix Under Review

#3 Updated by Ricardo Marques about 4 years ago

  • Status changed from Fix Under Review to Resolved

#4 Updated by Ernesto Puerta over 1 year ago

  • Project changed from mgr to Dashboard
  • Category changed from 139 to Component - RBD

Also available in: Atom PDF