Project

General

Profile

Actions

Bug #30387

closed

User can view bookmarks without assigning view_bookmarks permission in a role

Added by Shira Maximov over 4 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Users, Roles and Permissions
Target version:
-
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

Cloned from https://bugzilla.redhat.com/show_bug.cgi?id=1805740

Description of problem:
Non-admin user is able to view bookmarks without having view_bookmarks permissions.

Version-Release number of selected component (if applicable): Satellite 6.7

How reproducible: Always

Steps to Reproduce:
1. Create a user without any permission
2. Login to the satellite using the same user
3. Navigate to Administer -> Bookmarks.
4. User is able to view all bookmarks

Expected results: User should not able to view bookmarks without view_bookmarks permission


Related issues 1 (0 open1 closed)

Related to Foreman Remote Execution - Bug #32873: Do not check bookmark permissionsClosedAdam RuzickaActions
Actions

Also available in: Atom PDF