Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-72526

Impersonating user loads extra pages that user not authorized to view

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.21, 4.22
    • Management Console
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • Moderate
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      after impersonating a user, we still show some pages that the user doesn't have permission to view    

      Version-Release number of selected component (if applicable):

      4.21.0-0.nightly-2026-01-08-200223    

      How reproducible:

      Always    

      Steps to Reproduce:

      1. kube:admin user impersonate a normal user
      2. wait until the message 'You are impersonating User testuser-1. You are viewing all resources and roles this User can access. Stop Impersonating' appear in masthead, then check the pages

      Actual results:

      2. we still show Home -> Overview, Compute, Administration -> Cluster Settings, Namespaces pages
      
      when user tries to visit these pages, we will see Restricted access error    

      Expected results:

      2. should not show pages user doesn't have permission to view, even we wait for several minutes these pages still shown

      Additional info:

          

              rh-ee-leoli Leo Li
              rhn-support-yapei YaDan Pei
              YaDan Pei YaDan Pei
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: