-
Bug
-
Resolution: Done
-
Undefined
-
None
-
None
-
None
-
False
-
None
-
False
-
OCPSTRAT-386 - Multitenancy support in Network Observability for project admins
-
-
-
NetObserv - Sprint 235, NetObserv - Sprint 236, NetObserv - Sprint 237
I was able to see flows that shouldn't be accessible, when creating a user with 0 namespace accessible. Non-namespaced flows (such as flows involving node network, or cluster-external traffic) are visible to these users.
To reproduce this bug, follow steps described in https://issues.redhat.com/browse/NETOBSERV-901?focusedId=22219753&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-22219753 except you don't create a namespace for the test user.
- links to
- mentioned on
(56 mentioned on)