Uploaded image for project: 'Red Hat Fuse'
  1. Red Hat Fuse
  2. ENTESB-6084

Cannot restrict access to hawtio logs via RBAC configuration

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • jboss-fuse-6.3
    • jboss-fuse-6.2.1
    • Hawtio, Security
    • None
    • % %
    • Hide

      1. Set ACL entry in etc/auth/jmx.acl.io.fabric8.insight.LogQuery.cfg, restrict to only admins
      2. Log in as user with role Monitor
      3. Click on Logs tab, logs still are viewable.

      Show
      1. Set ACL entry in etc/auth/jmx.acl.io.fabric8.insight.LogQuery.cfg, restrict to only admins 2. Log in as user with role Monitor 3. Click on Logs tab, logs still are viewable.
    • Sprint 7 - towards CR2

    Description

      Even after adding appropriate ACL entries in "etc/auth/jmx.acl.io.fabric8.insight.LogQuery.cfg" (e.g. jsonQueryLogResults = admin), the user with a different role is still able to retrieve logs via Hawtio.

      Attachments

        Issue Links

          Activity

            People

              pantinor@redhat.com Paolo Antinori
              rhn-support-shiggs Stephen Higgs
              Josef Ludvicek Josef Ludvicek (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: