Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-3404

user with no permissions can access and edit deligate admin only policies

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 3.0.0, 2.2.0
    • Ranger
    • None

    Description

      From a user this was created by:
      -created new regular user in ranger with no groups or anything.
      -that user can see policies that he shouldn't (only ones with just delegate admin rights).
      -If a policy has a delegate admin, this user can see and edit it, but cannot add more permissions to the policy. Also, user can create a new policy, but it is only with no permissions and for delegating admin to other users - again with no permissions.
      -If policy has anything on top of delegate admin, then the user gets denied properly.

      Attachments

        Activity

          People

            abhayk Abhay Kulkarni
            abhayk Abhay Kulkarni
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: