Project

General

Custom queries

Profile

Actions

Feature #1050

closed

Foreman settings should not be viewed/edited by non admin users

Added by Ohad Levy over 13 years ago. Updated over 13 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Users, Roles and Permissions
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Related issues 1 (0 open1 closed)

Related to Foreman - Refactor #18440: Delete unused access_setting permissionClosedMarek Hulán02/09/2017Actions

Added by Ohad Levy over 13 years ago

Revision 1462d569 (diff)

fixes #1050 - Foreman settings should not be viewed/edited by non admin user

Added by Ohad Levy over 13 years ago

Revision 9d4999fe (diff)

refs #1050 removing model level authorization from settings table

this seems more trouble than its worth, as settings needs to be
checked/updated every time foreman is starting.

this leads to potenitail issue when login is enabled, or the admin user is missing etc
which can simply break foreman with very little benefit to security.

Actions

Also available in: Atom PDF