Uploaded image for project: 'OpenShift Pipelines'
  1. OpenShift Pipelines
  2. SRVKP-5831

Overview page, non-admin user is able to see data from namespaces which user don't have access to

XMLWordPrintable

    • False
    • None
    • False

      Description of problem:

      In Overview page, on login as non-admin user and selects "All" option in Project dropdown, user is able to see data from other namespaces which user doesn't have access to. For all-namespaces, UI is sending - for namespace value and summary API is returning data for all namespaces instead of all namespaces user is having access to. 

      Prerequisites (if any, like setup, operators/versions):

      Steps to Reproduce

      1. Install Pipelines operator
      2. Install tekton results
      3. Create some pipelineruns as admin user
      4. Login as non-admin user, and select All in Project dropdown

      Actual results:

      User is able to see data from namespaces which user don't have access to

      Expected results:

      User should see data from namespaces which user have access to.

      Reproducibility (Always/Intermittent/Only Once):

      Always

      Additional info (Such as Logs, Screenshots, etc):

       

       *

            Unassigned Unassigned
            rh-ee-lprabhu Lokananda Prabhu
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: