Bug #37531
openAutocomplete feature for search shows content from forbidden organization for user
Description
In the current version of Foreman, the auto-complete feature for search-bars does not respect organizations.
Steps to Reproduce:
1. Create two organization (org-1, org-2)
2. Create a user for org-2 (User cannot see org-1)
3. On UI page "Hosts->AllHosts" or "Hosts->ContentHosts" page write an option e.g. "lifecycle_environment = " or "content_view = " in search field.
4. We get a list of content from both organization org-1 and org-2.
Actual results:
We get a list of content from both organization org-1 and org-2 if we choose one of the search options above mentioned
Expected results:
We should get only the list recommended content from users' organization (org-2 in this case)
Files
Updated by The Foreman Bot 11 months ago
- Status changed from New to Ready For Testing
- Pull request https://github.com/theforeman/foreman/pull/10197 added
Updated by Thorben Denzer 10 months ago
ยท Edited
The created users may be given the administrator role.
Updated by Bernhard Suttner 6 months ago
Still possible on the new All Hosts Page: