Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-2891

Not authorised write operation does not get audit logged if log-read-only="false"

    XMLWordPrintable

Details

    Description

      This is because audit logging uses the controller lock to find out if the model was a write operation. If rbac is enabled and an operation is not authorised, the error happens before the controller lock is taken. So if audit log log-read-only="false" the failed operation does not get logged.

      Attachments

        Activity

          People

            bstansbe@redhat.com Brian Stansberry
            kkhan1@redhat.com Kabir Khan
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: