1.4.0.2
Progress
% Complete
Tickets Left
authorization issues
No open tickets in this milestone.
Closed tickets 2
Wednesday, November 09 2011
-
- State changed from needs_verification to resolved
verified that "user" default user cannot perform any actions on a fresh install
-
Greg Schueler commented at 12:58 PMFYI: user could create/modify jobs but cannot run anything on Nodes, this will fail with "No Matched Nodes"
-
-
- State changed from needs_verification to resolved
tested with api tests using api token auth
-
-
Greg Schueler commented at 12:14 PM(from [7b38b3e1bc99656927505787b71503a00664f1e4]) Use frameworkService for auth checks [#469] https://github.com/dtolabs/rundeck/commit/7b38b3e1bc9965692750578...
-
Greg Schueler commented at 12:14 PM(from [6abb827a3947be716cb1ba6f952ddf6de510f823]) Use frameworkService authorizeProjectResources
don't use session for project value
-
Greg Schueler commented at 12:14 PM(from [0d2c682c96e0048e72b8a0feb0004d59bc334024]) Add authorizeProjectResources for multiple resources
don't allow null project argument for authorize* methods
...
-
Greg Schueler commented at 12:14 PM(from [41b8a3fb03354953fa41f96b72294a7fbd55bb99]) Use job.project not session.project for auth check
Fixes some "null" project auth checks when using token base...
-
Greg Schueler commented at 12:13 PM(from [2661e7797aebb9274d5deb77b936650f075bb997]) Add create action to job auth for default apitoken policy [#469] https://github.com/dtolabs/rundeck/commit/26...
-
Greg Schueler created the ticket at 9:50 AMusing the job import API, the request may fail due to authorization, with the audit log containing:
2011-11-09 09:22:00,095 - Evaluating Decision for: res<type...
Monday, November 07 2011
-
Greg Schueler commented at 10:14 AM(from [251f65badb2cba4c06da7a0c23a6fcc262f0d51a]) Show clearer message when no project access [#467] https://github.com/dtolabs/rundeck/commit/251f65badb2cba4c...
-
Greg Schueler commented at 10:14 AM(from [f0c91fae384346f1c33c8e002c6c753c88858ab3]) Use title from controller model [#467] https://github.com/dtolabs/rundeck/commit/f0c91fae384346f1c33c8e002...
-
Greg Schueler commented at 10:14 AM(from [1a2365dda95dc176c37a5e7f30cd990e661e6363]) Fix ordering of filter checks [#467] https://github.com/dtolabs/rundeck/commit/1a2365dda95dc176c37a5e7f3...
-
Greg Schueler commented at 10:14 AM(from [43f6a9fb898b1bf4c80fe6ac85a02dbb46150a7d]) Remove getFramework(), use getFrameworkNodeName [#467] https://github.com/dtolabs/rundeck/commit/43f6a9fb898b...
-
Greg Schueler commented at 10:14 AM(from [dccac21fd5f1c5250bc12b5fd0e43df85f85b1c4]) Add DenyAuthorization impl, refactor to BaseAuthorization [#467] https://github.com/dtolabs/rundeck/commit/dc...
Friday, November 04 2011
-
Greg Schueler created the ticket at 4:56 PMa user not authorized via aclpolicy can still perform unauthorized actions:
user can log in and create projects, jobs, run jobs etc.
No messages in this milestone.