Project

General

Profile

Actions

Bug #38727

closed

Autocomplete feature for search shows content that should be forbidden by RBAC

Added by Adam Ruzicka 4 months ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

1. Create domain called foo
2. Create a domain called bar
3. Create a role
4. Add view_domains permission to it, limit it by search to name ~ f*
5. Create a user
6. Give the role to the user
7. Log in as user
8. Go to infrastructure > domains
9. Put name = into the search bar

Expected results:
Autocomplete offers only domain foo.

Actual results:
Autocomplete offers both bar and foo domains.


Related issues 2 (2 open0 closed)

Related to Foreman - Bug #37531: Autocomplete feature for search shows content from forbidden organization for userReady For TestingThorben DenzerActions
Related to Katello - Bug #38656: Autocomplete feature for search shows content from forbidden organization for userReady For TestingAdam RuzickaActions
Actions #1

Updated by Adam Ruzicka 4 months ago

  • Related to Bug #37531: Autocomplete feature for search shows content from forbidden organization for user added
Actions #2

Updated by Adam Ruzicka 4 months ago

This issue talks about things which should be explicitly allowed (or forbidden) by RBAC, while 37531 talks about taxonomy scoping.

Actions #3

Updated by The Foreman Bot 4 months ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/10645 added
Actions #4

Updated by Adam Ruzicka 4 months ago

  • Red Hat JIRA set to SAT-36586
Actions #5

Updated by The Foreman Bot 4 months ago

  • Fixed in Releases 3.17.0 added
Actions #6

Updated by Adam Ruzicka 4 months ago

  • Status changed from Ready For Testing to Closed
Actions #7

Updated by Adam Ruzicka 4 months ago

  • Target version set to 3.16.1
Actions #8

Updated by Adam Ruzicka 4 months ago

  • Related to Bug #38656: Autocomplete feature for search shows content from forbidden organization for user added
Actions

Also available in: Atom PDF