Uploaded image for project: 'Hybrid Cloud Console'
  1. Hybrid Cloud Console
  2. RHCLOUD-39185

User with no specific remediations roles, and the rhel viewer role can download playbooks.

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • Unset
    • None
    • Important

      Description of Problem

      I have created a user (policy-rhel-viewer-1) that does not have any remediations roles (I removed these from the default/custom access group) and does have the RHEL viewer role (no RHEL admin or rhel operator role). This user can download remediations playbooks.  
      The permissions in "My User Access" only have one line for remediations and it is "read". 

      How reproducible

      Always

      Steps to Reproduce

      1. create a user that does not have any remediations roles (I removed these from the default/custom access group) and does have the RHEL viewer role (no RHEL admin or rhel operator role). A group with the rhel viewer role will need to be created and the user added to it. 
      2. Go to the "Automation Toolkit" > "Remediations"  view
      3. Select a checkbox beside a playbook and click the "Download playbook" button.
      4. *If no playbooks exist in the view, another user with write permissions is going to need to click on a system in the system view, select an advisory, click on "Plan remediation' and follow the modals to generate a playbook.

      Actual Behavior

      The modals are displayed to download a playbook (I filled these out and a playbook is generated)

      Expected Behavior

      The "Download playbook" button should remain disabled when a playbook is selected

      Business Impact / Additional info

              Unassigned Unassigned
              prichard@redhat.com PJ Richardson
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: