Uploaded image for project: 'Red Hat Fuse'
  1. Red Hat Fuse
  2. ENTESB-10827

[Hawtio + Keycloak] User with insufficient rights can have access to all tabs from menu

    XMLWordPrintable

Details

    • Bug
    • Resolution: Not a Bug
    • Major
    • None
    • fuse-7.4-GA
    • Hawtio
    • None
    • % %
    • Hide
      1. clone https://github.com/vramik/keycloak/tree/KEYCLOAK-10417-fuse-adapter-test (I'm using this commit)
      2. mvn clean install -f keycloak/pom.xml -DskipTests -Pdistribution
      3. mvn clean install -f keycloak/testsuite/integration-arquillian/servers/app-server/karaf/fuse7x/pom.xml -Dfuse7x.version=7.4.0.fuse-740019
      4. mvn clean install -f keycloak/testsuite/integration-arquillian/tests/base/pom.xml -Dtest=org.keycloak.testsuite.adapter.example.fuse.FuseAdapterTest#hawtio2LoginTest -Dauth.server.ssl.required=false -Dadditional.fuse.repos=http://indy.psi.redhat.com/api/group/static/@id=pnc -Djs.browser=chrome -Papp-server-fuse7x -Djs.chromeArguments=""
      5. You have to run the test several times, the bug is happening only sometimes
      Show
      clone https://github.com/vramik/keycloak/tree/KEYCLOAK-10417-fuse-adapter-test (I'm using this commit ) mvn clean install -f keycloak/pom.xml -DskipTests -Pdistribution mvn clean install -f keycloak/testsuite/integration-arquillian/servers/app-server/karaf/fuse7x/pom.xml -Dfuse7x.version=7.4.0.fuse-740019 mvn clean install -f keycloak/testsuite/integration-arquillian/tests/base/pom.xml -Dtest=org.keycloak.testsuite.adapter.example.fuse.FuseAdapterTest#hawtio2LoginTest -Dauth.server.ssl.required=false -Dadditional.fuse.repos= http://indy.psi.redhat.com/api/group/static/@id=pnc -Djs.browser=chrome -Papp-server-fuse7x -Djs.chromeArguments="" You have to run the test several times, the bug is happening only sometimes

    Description

      I'm using demorealm.json for configuration of the realm in Keycloak. I'm testing users from there:
      root (pass: password) - does have access to all tabs from the menu
      roles: "Auditor", "Maintainer","Operator", "viewer", "Administrator", "manager", "jmxAdmin", "ssh", "admin", "SuperUser","Deployer"
      mary (pass: password) - does have access only to Connect tab
      roles: ssh

      When I'm trying to access these links, it sometimes happens, that mary can have access to all of them:

      Attachments

        1. 20190722-161048.png
          20190722-161048.png
          208 kB
        2. demorealm.json
          10 kB
        3. dump-test-failed.txt.gz
          2.52 MB
        4. dump-test-ok.txt.gz
          2.58 MB

        Activity

          People

            ggrzybek Grzegorz Grzybek
            ldrozdo Lucia Drozdova
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: