View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0000656 | bareos-core | webui | public | 2016-05-09 13:10 | 2016-05-16 10:51 |
Reporter | hostedpower | Assigned To | |||
Priority | urgent | Severity | feature | Reproducibility | always |
Status | closed | Resolution | duplicate | ||
Platform | Linux | OS | Debian | OS Version | 8 |
Product Version | 15.2.3 | ||||
Summary | 0000656: Not possible to limit permissions properly | ||||
Description | Hi, I tried to create a limited webui. However it does not seem possible to configure it to limit it for 1 client. I can limit the permissions so only 1 client can be restored, but whatever I try all jobs, clients, resources etc are shown. Probably this is the list command. The list command should limit to show only stuff related to the Job and Client ACL's. I don't understand why this is not the case, many other programs work like that :( It limits the otherwise great app severly since we want to give other users permissons to login, but they should not see other clients information :( Example console: # status, run, .status, restore, list, help, .jobs, .clients, .filesets, .pools, .storage, .defaults, .backups} Profile { Name = kreative CommandACL = cancel, messages, rerun, restore, run, rerun, show, status, version, .api, list, jobs, .bvfs_* Job ACL = RestoreFiles, backup-vps52371 Schedule ACL = *all* Catalog ACL = *all* Pool ACL = localserver, *vps52371* Storage ACL = localserver, *vps52371* Client ACL = vps52371 FileSet ACL = *all* Where ACL = *all* } So when I remove the list, I can no longer use the webui at all to do restores. With the list enabled way to much info is shown about resources the client should not have access to. | ||||
Tags | No tags attached. | ||||
duplicate of | 0000628 | closed | output of list command not restricted for own jobs/clients on restricted consoles with ACLs |
Please search first to see if you are not entering an duplicate. If you find this such a problem there is also the possibility to sponsor the development of this feature. You seem to earn money with our product so maybe we can also ask you to share some of that with us to develop the wanted feature via funded development. Try sales@bareos.com |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2016-05-09 13:10 | hostedpower | New Issue | |
2016-05-09 18:52 | mvwieringen | Relationship added | duplicate of 0000628 |
2016-05-09 18:55 | mvwieringen | Note Added: 0002261 | |
2016-05-09 18:55 | mvwieringen | Status | new => feedback |
2016-05-16 10:51 | mvwieringen | Status | feedback => closed |
2016-05-16 10:51 | mvwieringen | Resolution | open => duplicate |