apache / apache/cloudstack

Switching to project view not working when user is assigned custom Project Role

Offen
#14,014 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
component:projects component:UI type:regression
Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 19 Std.
Gemergte PRs (30 T.)
32

Beschreibung

### problem

If account/user is added to the project with custom role (even if role permisions are "allow *") user can login to CS successfully but switching to project view will fail and generate multiple errors: "

```
The given command 'listApis' either does not exist, is not available for user. Unable to proceed. Please contact your administrator."
The given command 'listZones' either does not exist, is not available for user. Unable to proceed. Please contact your administrator.
The given command 'listCapabilities' either does not exist, is not available for user. Unable to proceed. Please contact your administrator.
...
```

Image

On browser console indeed you can see that request:
` /client/api/?command=listApis&response=json&sessionkey=xxx&projectid=xxx`
returns:
`{"listapisresponse":{"uuidList":[],"errorcode":401,"cserrorcode":9999,"errortext":"The given command 'listApis' either does not exist, is not available for user."}}
`
If user is added to the project with Admin or Regular Type without any project role, switching to project view works correctly.

Switching to project view using custom Project Roles in 4.22.1.0 works correctly.
Also using UI ver. 4.22.1.1 and Api ver: 4.22.1.0 works correctly.

No additional logs available in:
```
cloudstack/management/apilog.log
cloudstack/management/management-server.log
```

### versions

ACS: 4.22.1.1

### The steps to reproduce the bug

1. Create new project "Test"
2. Create Project Role with "allow *" permission
3. Add non-admin user to project with that Project Role
4. Switch to Project View of "Test" project

### What to do about it?

Please track the root cause and fix the bug

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Reproduzieren Sie den Fehler mit einer benutzerdefinierten Project Role, die "allow *" gewährt, und untersuchen Sie anschließend die Projektansichtsanforderungen für listApis, listZones und listCapabilities und vergleichen Sie sie mit einer Admin- oder Regular-Projektmitgliedschaft. Überprüfen Sie das Verhalten in den API/UI-Versionen 4.22.1.1 und 4.22.1.0. Als abgeschlossen gilt die Aufgabe, wenn ein Benutzer mit einer benutzerdefinierten Rolle ohne Autorisierungsfehler in die Projektansicht wechseln kann und die aufgeführten Anforderungen erfolgreich sind.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
api, authorization
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.