apache / apache/cloudstack

Switching to project view not working when user is assigned custom Project Role

Open
#14,014 1 comment 0 reactions 0 assignees View on GitHub
component:projects component:UI type:regression
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

### problem

If account/user is added to the project with custom role (even if role permisions are "allow *") user can login to CS successfully but switching to project view will fail and generate multiple errors: "

```
The given command 'listApis' either does not exist, is not available for user. Unable to proceed. Please contact your administrator."
The given command 'listZones' either does not exist, is not available for user. Unable to proceed. Please contact your administrator.
The given command 'listCapabilities' either does not exist, is not available for user. Unable to proceed. Please contact your administrator.
...
```

Image

On browser console indeed you can see that request:
` /client/api/?command=listApis&response=json&sessionkey=xxx&projectid=xxx`
returns:
`{"listapisresponse":{"uuidList":[],"errorcode":401,"cserrorcode":9999,"errortext":"The given command 'listApis' either does not exist, is not available for user."}}
`
If user is added to the project with Admin or Regular Type without any project role, switching to project view works correctly.

Switching to project view using custom Project Roles in 4.22.1.0 works correctly.
Also using UI ver. 4.22.1.1 and Api ver: 4.22.1.0 works correctly.

No additional logs available in:
```
cloudstack/management/apilog.log
cloudstack/management/management-server.log
```

### versions

ACS: 4.22.1.1

### The steps to reproduce the bug

1. Create new project "Test"
2. Create Project Role with "allow *" permission
3. Add non-admin user to project with that Project Role
4. Switch to Project View of "Test" project

### What to do about it?

Please track the root cause and fix the bug

Contributor guide

Open the contributing guide

Research direction

Reproduce the failure with a custom Project Role granting "allow *", then inspect the project-view requests for listApis, listZones, and listCapabilities and compare them with Admin or Regular project membership. Check the behavior across API/UI versions 4.22.1.1 and 4.22.1.0. Done means a custom-role user can switch to project view without authorization errors and the listed requests succeed.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, authorization
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.