Bug #17266

Fix tests that depend on CVE 2016-7078

Added by Daniel Lobato Garcia 11 months ago. Updated 7 months ago.

Status:Closed
Priority:Normal
Assigned To:Daniel Lobato Garcia
Category:-
Target version:Foreman - Team Daniel - Iteration 9
Difficulty: Pull request:https://github.com/Katello/katello/pull/6447, https://github.com/theforeman/foreman/pull/3954, https://github.com/theforeman/foreman/pull/3961
Bugzilla link:
Story points-
Velocity based estimate-
ReleaseKatello 3.4.0Release relationshipAuto

Description

Following #16982 - there were some tests in Katello (much less than in Foreman due to the requirement for Orgs) that relied upon this vulnerability to work.


Related issues

Copied from Foreman - Bug #16982: CVE-2016-7078 - User with no organizations or locations c... Closed 10/18/2016

Associated revisions

Revision 236abac4
Added by Daniel Lobato Garcia 7 months ago

Fixes #17266 - Fix tests that depend on CVE 2016-7078

A small number of tests in the Katello codebase depended on regular
users being able to see objects without organization/location. This is
now fixed in core through a CVE (users shouldn't view stuff they're not
scoped to see), so in order for Jenkins to pass, we need to make Katello
tests pass with it too.

History

#1 Updated by Daniel Lobato Garcia 11 months ago

  • Copied from Bug #16982: CVE-2016-7078 - User with no organizations or locations can see all resources added

#2 Updated by The Foreman Bot 11 months ago

  • Pull request https://github.com/Katello/katello/pull/6447 added

#3 Updated by Dominic Cleal 10 months ago

  • Release deleted (1.13.2)

#4 Updated by Daniel Lobato Garcia 10 months ago

  • Target version changed from Team Daniel - iteration 3 to Team Daniel - iteration 6

#5 Updated by Justin Sherrill 10 months ago

  • Release set to Katello Backlog

#6 Updated by The Foreman Bot 8 months ago

  • Release deleted (Katello Backlog)

#7 Updated by Justin Sherrill 7 months ago

  • Release set to Katello Backlog

#8 Updated by Daniel Lobato Garcia 7 months ago

  • Target version changed from Team Daniel - iteration 6 to Team Daniel - Iteration 9

#9 Updated by The Foreman Bot 7 months ago

  • Release deleted (Katello Backlog)

#10 Updated by Anonymous 7 months ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

#11 Updated by Eric Helms 7 months ago

  • Release set to Katello 3.4.0

Also available in: Atom PDF