-
Bug
-
Resolution: Done
-
Major
-
6.1.0
-
None
-
x86_64 Linux
Description of problem:
When admin role is given to an org. unit or a repository and the admin deploys a project and starts some process instances then privileges are ignored in BC. Eg. user with analyst role can build&deploy any project from org. unit/repository or cancel process instances started by admin.
Version-Release number of selected component (if applicable):
BPMS 6.1.0.ER6
How reproducible:
Always
Steps to Reproduce:
1. Add admin role to org. unit/repository in kie-config-cli: add-role-org-unit or add-role-repo
2. Login to the BC as user with admin role and start some process instances. Logout.
3. Login to the BC as user with analyst role and try to list org. unit/repository and try to cancel process instances started by admin.
Actual results:
Analyst has rights of admin
Expected results:
the OU or a repository and projects are hidden to analyst.
Additional info:
- is related to
-
RHBRMS-375 Access restrictions to assets does not work with custom roles
- Verified
-
RHBRMS-2300 User with no privileges for repository can view and modify assets in that repository
- Verified
-
RHBPMS-831 Roles added to org. unit and repository are ignored by Business Central
- Verified
- relates to
-
RHBRMS-375 Access restrictions to assets does not work with custom roles
- Verified
-
RHBRMS-2300 User with no privileges for repository can view and modify assets in that repository
- Verified
-
RHBPMS-831 Roles added to org. unit and repository are ignored by Business Central
- Verified