Uploaded image for project: 'Red Hat 3scale API Management'
  1. Red Hat 3scale API Management
  2. THREESCALE-11068

Member user in Analytics group getting Access Denied when accessing the Product analytics page

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 2.14.0 GA, 2.15.0 GA
    • System
    • False
    • None
    • False
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started

      Steps to reproduce:

      • Login in the Admin Portal with a member user that has only "Access & query analytics" permissions - for 6 products (it can be any 6 products)
      • Navigate to the dashboard and see that 5 products are listed
      • Try to access the view "Explore all Products" so that the user logged in can find the 6th Product link to access the analytics view and you'll get the "Access Denied" error

      When assigning Analytics permissions (Access & query analytics) to a member user and this user tries to access a Products page through the Admin Portal, it's returning the message Access Denied. User cannot navigate to a specific product, nor see all products that should see and access their analytics. From dashboard is possible to navigate only to latest updated products (this workflow works) but not for older products.
      That is, the user cannot access the link which would take them to the view that they do have access to because if that Product is not rendered in the Dashboard view (only 5 products are listed there) then there will always be n products missing for every 5 + nth Product they have permission to access.

      See also THREESCALE-7491

            [THREESCALE-11068] Member user in Analytics group getting Access Denied when accessing the Product analytics page

            Joan Lledo added a comment -

            rhn-support-keprice Thanks for clarifying. I think the issue can be moved to "To Develop" now

            Joan Lledo added a comment - rhn-support-keprice Thanks for clarifying. I think the issue can be moved to "To Develop" now

            Kevin Price added a comment -

            rh-ee-jlledo I updated the steps to reproduce with more specific instructions. The issue is primarily about the fact the user cannot access the link which would take them to the view that they do have access to because if that Product is not rendered in the Dashboard view (only 5 products are listed there) then there will always be n products missing for every 5 + nth Product they have permission to access.

            Kevin Price added a comment - rh-ee-jlledo I updated the steps to reproduce with more specific instructions. The issue is primarily about the fact the user cannot access the link which would take them to the view that they do have access to because if that Product is not rendered in the Dashboard view (only 5 products are listed there) then there will always be n products missing for every 5 + nth Product they have permission to access.

            Joan Lledo added a comment -

            dhlavacd@redhat.com 

            I can't reproduce this: I followed the instructions and I can see the analytics. I'm attaching a couple of screenshots for you to verify, just in case I did something wrong.

            Joan Lledo added a comment - dhlavacd@redhat.com   I can't reproduce this: I followed the instructions and I can see the analytics. I'm attaching a couple of screenshots for you to verify, just in case I did something wrong.

            No, its the same problem but with products assigned to user. There is no way how user can see products analytics unless he enter specific url with product ID

            Dominik Hlavac Duran added a comment - No, its the same problem but with products assigned to user. There is no way how user can see products analytics unless he enter specific url with product ID

            dhlavacd@redhat.com, is this a duplicate of THREESCALE-7491?

            Catherine Bartlett added a comment - dhlavacd@redhat.com , is this a duplicate of THREESCALE-7491 ?

              Unassigned Unassigned
              dhlavacd@redhat.com Dominik Hlavac Duran
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: