Project

General

Profile

Actions

Bug #6551

closed

roles: UI neither raise any error not adds the content-hosts to selected collection via a normal user

Added by Walden Raines almost 10 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Web UI
Target version:
Difficulty:
easy
Triaged:
Yes
Fixed in Releases:
Found in Releases:

Description

Cloned from https://bugzilla.redhat.com/show_bug.cgi?id=1112644
Description of problem:
I was trying to manage host-collections via a normal user. I created a user and assigned all required perms. So user was able to create collection but not able to add selected content-hosts to it. Content-hosts were listed under host-collection. when I clicked add-selected, nothing happened on UI, neither the validation error raised on UI nor content-host was added to collection.

Version-Release number of selected component (if applicable):
sat6 beta snap10 compose2

How reproducible:
always

Steps to Reproduce:
1. create a role with perms as mentioned in screenshot
2. create few dummy content-host
2. assign that role to a user
3. login with user and try to add created content-hosts to host-collection

Actual results:
UI neither raised any error not add the selected hosts to host-collection

Expected results:
In any case, this situation is very confusing, because neither I get 403 forbidden message nor I was able to add hosts to host-collection.

If I'm missing any permission then a error should be raised that user is not authorized.

Additional info:

Actions #1

Updated by Walden Raines almost 10 years ago

  • Status changed from New to Assigned
Actions #2

Updated by Walden Raines almost 10 years ago

  • Status changed from Assigned to Closed

In order to add content hosts to a host collection you must have the permission "edit_content_host" for the content host you wish to add to the host collection as well as the permission "edit_host_collection" for the host collection you are adding the content host to.

If we you to have both permissions then you would be able to gain an implicit "edit_content_hosts" for a content host by adding the content host to a host collection since you could then perform bulk actions on the content host.

Actions #3

Updated by Walden Raines almost 10 years ago

  • Status changed from Closed to Assigned

Will ensure a 403 message is displayed in this case.

Actions #4

Updated by Walden Raines almost 10 years ago

  • Status changed from Assigned to Ready For Testing
Actions #5

Updated by Eric Helms almost 10 years ago

  • Category set to Web UI
  • Target version set to 49
  • Difficulty set to easy
  • Triaged changed from No to Yes
Actions #6

Updated by The Foreman Bot almost 10 years ago

  • Pull request https://github.com/Katello/katello/pull/4413 added
  • Pull request deleted ()
Actions #7

Updated by Walden Raines almost 10 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions #8

Updated by Eric Helms over 9 years ago

  • translation missing: en.field_release set to 13
Actions

Also available in: Atom PDF