Project

General

Profile

Actions

Bug #13912

closed

Unauthorized user can remove host parameter

Added by Thomas Bétrancourt about 8 years ago. Updated about 8 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
Users, Roles and Permissions
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

Hello,

I defined a Role (filters in attachment) which allows user to Edit host information (organization, host group, etc...).

On "Parameters" tab, the user cannot edit or add parameter, but he can Remove Host parameters (cf attachments).

Expected behaviour : deny removing parameter and remove the "Remove parameter" button from the page

PS : Found in Foreman included in Satellite 6.1.7


Files

edit_host_parameters.png View edit_host_parameters.png 64.1 KB Thomas Bétrancourt, 02/26/2016 02:50 AM
role_filters.png View role_filters.png 87.1 KB Thomas Bétrancourt, 02/26/2016 02:50 AM
Actions #1

Updated by Dominic Cleal about 8 years ago

  • Status changed from New to Rejected

Can't reproduce on a current stable version, link is disabled. Please file bugs against Satellite with Red Hat instead.

Actions

Also available in: Atom PDF