-
Feature Request
-
Resolution: Unresolved
-
Normal
-
None
-
2.6
-
False
-
-
False
1. What is the nature and description of the request?
This RFE is intended to mitigate that risk and address the identified security concern for the bank. Customer is working on permission for end users in AAP 2.6 openshift deployment where they have created a normal user with no permission but user is still able to see the admin details in access management – users
2. Why does the customer need this? (List the business requirements here)
This presents a security concern for the bank. Currently, a standard user can view information about both system administrators and other users within the organization, including usernames and email addresses. Because Active Directory will be used for authentication, exposing domain usernames to basic users increases the risk of credential-based attacks. An attacker could leverage this information to attempt brute-force or credential-stuffing attacks against applications outside of AAP.
3. How would you like to achieve this? (List the functional requirements here)
Normal should not allow to see Access Management — Users in controller UI normal user can only see it's detail's not the admin's detail's not even in view mode.