-
Bug
-
Resolution: Done-Errata
-
Normal
-
None
-
2
-
False
-
foreman-3.16.0.1
-
Satellite Endeavour Sprint 3, Satellite Endeavour Sprint 4, Satellite Endeavour Sprint 5, Satellite Endeavour Sprint 6
-
sat-endeavour
-
None
-
None
-
None
-
None
-
No
Description of problem:
Autocomplete in search boxes seems to ignore users' permissions, possibly showing things the users wouldn't be allowed to see otherwise.
How reproducible:
Always
Is this issue a regression from an earlier version:
Most likely not
Steps to Reproduce:
- Create domain called foo
- Create a domain called bar
- Create a role
- Add view_domains permission to it, limit it by search to name ~ f*
- Create a user
- Give the role to the user
- Log in as user
- Go to infrastructure > domains
- Put {{name = }} into the search bar
Actual behavior:
Autocomplete offers both bar and foo domains.
Expected behavior:
Autocomplete offers only domain foo.
- links to
-
RHBA-2025:155337
Important: Satellite 6.18.0 new version release