Uploaded image for project: 'OCMUI - OpenShift Cluster Manager UI'
  1. OCMUI - OpenShift Cluster Manager UI
  2. OCMUI-729

[OCM UI] A "Cluster Autoscaler Editor" role allowed to execute other actions than cluster autoscaler settings.

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • None

      Description of problem:

      An org member user has granted with role permission "Cluster Autoscaler Editor" for a cluster. But in org member user login session from OCM UI, the below action are permitted wrongly.

      1. Allowed to create a cluster administrative users (under cluster roles and access) to the cluster.
      2. Allowed to grant a AWS infrastructure access roles from the cluster.
      3. Allowed to modify cluster ingress definitions from networking tab.
      4. Allowed to edit the the load balancer count/Definition from Cluster's actions menu.
      5. Allowed to Hibernate the cluster from cluster's action menu.
      6. Allowed to click "Add machine pool" button but creation of machine pool is forbidden

      How reproducible:

       Always

      Steps to reproduce:

      1. Launch OCM UI staging and login as org-admin user.
      2. Open a OSD cluster.
      3. Go to access control tab > OCM roles and access , click "Grant" button.
      4. Input Redhat login with a valid user name (ex: use a org-member user)
      5. Select Role as Cluster Autoscaler editor and Click on "Grant role".
      6. Login to OCM UI Staging with the user granted permission in step 4 .
      7. Select and Open  the cluster(same as step 2).
      8. Perform all above actions.

      Actual results:

      The user allowed to perform all above mentioned action wrongly against the cluster

      Expected results:
      The user with "Cluster autoscaler editor" should have only access to modify cluster autoscaler settings. All other actions should be restricted from UI.

            Unassigned Unassigned
            jmekkatt@redhat.com Jayakrishnan Mekkattillam
            Zhaohua Sun Zhaohua Sun
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated: