apache / apache/cloudstack

UI: a role denied one non-essential bootstrap API (e.g. listLdapConfigurations) fails to load the entire console

Offen Anfängerfreundlich
#13,912 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
component:UI
Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 19 Std.
Gemergte PRs (30 T.)
32

Beschreibung

### problem

The web console fails to load entirely for any role denied one non-essential bootstrap read. [`GetInfo`](https://github.com/apache/cloudstack/blob/main/ui/src/store/modules/user.js#L326) runs several independent calls under a single shared `Promise` and wires several to the same `reject`, including [`listLdapConfigurations`](https://github.com/apache/cloudstack/blob/main/ui/src/store/modules/user.js#L493-L497), which only sets a flag. When a role denies it the 432 rejects the shared promise before [`listApis`](https://github.com/apache/cloudstack/blob/main/ui/src/store/modules/user.js#L415) can resolve it (a race the small query usually wins), so `GetInfo` rejects and the [router guard](https://github.com/apache/cloudstack/blob/main/ui/src/permission.js#L150-L167) logs the user out instead of building routes. The tolerant pattern sits right beside it: [`listNetworkServiceProviders`](https://github.com/apache/cloudstack/blob/main/ui/src/store/modules/user.js#L485) swallows its own error and the console still loads (`listGuiThemes` likewise).

**Expected:** a denied non-essential read degrades like `listNetworkServiceProviders`/`listGuiThemes`. **Actual:** blank console, redirect to `/user/login`.

### versions

4.22 and current `main`. Client-side UI only; hypervisor/storage/network irrelevant.

### The steps to reproduce the bug

1. Create a custom role (e.g. from the DomainAdmin base type) that denies `listLdapConfigurations`.
2. Assign an account to it.
3. Log in to the web UI — the console never renders and you are redirected to login.

### What to do about it?

Give `listLdapConfigurations` (and any non-essential bootstrap read) its own `.catch` that defaults the flag, as [`listNetworkServiceProviders`](https://github.com/apache/cloudstack/blob/main/ui/src/store/modules/user.js#L485) already does. The underlying hazard is the shared `resolve`/`reject` across independent calls in `GetInfo`; reserve `reject` for genuinely essential calls such as `listApis`.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne in ui/src/store/modules/user.js bei GetInfo, insbesondere bei listLdapConfigurations und den toleranten Handlern listNetworkServiceProviders/listGuiThemes. Überprüfe ui/src/permission.js, um den Fehlerpfad der Routensicherung zu verstehen. Die Änderung ist abgeschlossen, wenn ein verweigerter, nicht essenzieller Bootstrap-Lesevorgang sein Flag standardmäßig setzt, ohne GetInfo abzulehnen, sodass die Konsole geladen wird, statt zu /user/login umzuleiten.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
javascript
Bereich
frontend
Issue-Typ
Bug
Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Aktivitätsstatus
Aktiv
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
85/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.