Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

Document if jobs can be hidden but be executed from other

#306

Test disallowing workflow_read but allowing workflow_run in order to see if a hidden subjob can still be executed from another (workflow) job.

Reported by Alex-SF · May 26th, 2011 @ 04:57 PM

State: resolved
Milestone: Rundeck 1.2.1
Assigned to: nobody

Activity

  1. Alex-SF
    Alex-SF
    • Tag changed from documentation to customer request, documentation

    May 31st, 2011 @ 02:44 PM

  2. Alex-SF
    Alex-SF

    The underlying goal is to reduce the clutter in the job list. For example, there may be a handful of top level processes that should be visible. These top level jobs may be constructed from lower level "helper jobs" that should not be visible since they should normally be run by themselves.

    May 31st, 2011 @ 03:10 PM

  3. Alex-SF
    Alex-SF

    Adding job definition describing trivial multi-job workflow structure in a group named "#306".

    The following aclpolicy hides the jobs that are not meant to be visible in the gui.

    <policies>
      <policy description="User group that has limited access.">
        <context project="*">
          <command group="#306" job="Restart" actions="workflow_run,workflow_read"/>
          <command group="#306" job="stop" actions="workflow_run"/>
          <command group="#306" job="stop" actions="workflow_run"/>
        </context>
        <by>
          <group name="user"/>
        </by>
      </policy>
    </policies>
    

    May 31st, 2011 @ 03:22 PM

  4. Greg Schueler
    Greg Schueler

    any job can be run as a subjob (auth is not checked)

    also, authorization checks for grails actions (pages) use the mapped roles, not the aclpolicy. so, e.g. you can still view the /job/show/id page for any of those jobs where there is no workflow_read authorization. Likewise, mapped roles must assign workflow_update to one of the user's roles to be able to edit a job, even if aclpolicy allows * actions.

    another point:

    Job listings are filtered by aclpolicy. So the main Jobs page will not show unauthorized jobs. Also, job reference selection in the job edit page will not show unauthorized jobs.

    May 31st, 2011 @ 03:52 PM

  5. Deleted User
  6. Deleted User

Please Sign in or create a free account to add a new ticket.

With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.