Project

General

Profile

Actions

Bug #16807

closed

test mail button requires excessive priviledges

Added by Steve Traylen almost 8 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
E-Mail
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

When trying the the test mail button I believe I run into a missing ACL?

016-10-05 13:40:44 [app] [I] Started PUT "/users/5-straylen/test_mail" for 188.184.65.139 at 2016-10-05 13:40:44 +0200
2016-10-05 13:40:44 [app] [I] Processing by UsersController#test_mail as */*
2016-10-05 13:40:44 [app] [I] Parameters: {"user_email"=>"", "id"=>"5-straylen"}
2016-10-05 13:40:44 [app] [I] Rendered common/403.html.erb (1.4ms)
2016-10-05 13:40:44 [app] [I] Filter chain halted as :authorize rendered or redirected

the button works as admin.

Comment from IRC:

The button requires that the user has either create or edit_users, which is clearly unnecessary.


Related issues 1 (0 open1 closed)

Has duplicate Foreman - Bug #20410: Getting 403 forbidden error while setting the email preference or sending the test email with a normal user with viewer access Duplicate07/26/2017Actions
Actions #1

Updated by The Foreman Bot about 7 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/4595 added
Actions #2

Updated by Ohad Levy about 7 years ago

  • Translation missing: en.field_release set to 240
Actions #3

Updated by Amir Fefer about 7 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions #4

Updated by Daniel Lobato Garcia about 7 years ago

  • Translation missing: en.field_release changed from 240 to 266
Actions #5

Updated by Daniel Lobato Garcia almost 7 years ago

  • Has duplicate Bug #20410: Getting 403 forbidden error while setting the email preference or sending the test email with a normal user with viewer access added
Actions #6

Updated by Tomer Brisker almost 7 years ago

  • Assignee changed from Steve Traylen to Amir Fefer
Actions

Also available in: Atom PDF