Project

General

Profile

Actions

Bug #38727

closed

Autocomplete feature for search shows content that should be forbidden by RBAC

Added by Adam Ruzicka 5 months ago. Updated 5 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

1. Create domain called foo
2. Create a domain called bar
3. Create a role
4. Add view_domains permission to it, limit it by search to name ~ f*
5. Create a user
6. Give the role to the user
7. Log in as user
8. Go to infrastructure > domains
9. Put name = into the search bar

Expected results:
Autocomplete offers only domain foo.

Actual results:
Autocomplete offers both bar and foo domains.


Related issues 2 (2 open0 closed)

Related to Foreman - Bug #37531: Autocomplete feature for search shows content from forbidden organization for userReady For TestingThorben DenzerActions
Related to Katello - Bug #38656: Autocomplete feature for search shows content from forbidden organization for userReady For TestingAdam RuzickaActions
Actions

Also available in: Atom PDF