[2.5, RBAC, API, UI] Auditors are allowed to create devices

Bug #1812402 reported by Björn Tillenius
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
MAAS
Fix Released
High
Alberto Donato
2.5
Fix Committed
Medium
Alberto Donato

Bug Description

This is with MAAS 2.5.1-7489-g2f25a2cc0-0ubuntu1~18.04.1 and RBAC enabled.

I have a user that has no other roles in MAAS than auditor on a resource
pool.

Even though an auditor is supposed to have only view permissions, he
can still create new devices, both in the UI and in the API.

Tags: api rbac ui

Related branches

tags: added: api rbac ui
Changed in maas:
status: New → Triaged
importance: Undecided → High
milestone: none → 2.5.1
Changed in maas:
milestone: 2.5.1 → 2.5.2
Changed in maas:
milestone: 2.5.2 → 2.5.3
Changed in maas:
milestone: 2.5.3 → 2.6.0beta2
Changed in maas:
milestone: 2.6.0beta2 → 2.6.0rc1
Alberto Donato (ack)
Changed in maas:
assignee: nobody → Alberto Donato (ack)
Alberto Donato (ack)
Changed in maas:
status: Triaged → In Progress
Changed in maas:
milestone: 2.6.0rc1 → 2.6.0rc2
milestone: 2.6.0rc2 → 2.6.0rc1
Changed in maas:
milestone: 2.6.0rc1 → 2.6.0rc2
Changed in maas:
status: In Progress → Fix Committed
Changed in maas:
milestone: 2.6.0rc2 → 2.6.0rc1
Changed in maas:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.