View Issue Details

IDProjectCategoryView StatusLast Update
0000656bareos-corewebuipublic2016-05-16 10:51
Reporterhostedpower Assigned To 
PriorityurgentSeverityfeatureReproducibilityalways
Status closedResolutionduplicate 
PlatformLinuxOSDebianOS Version8
Product Version15.2.3 
Summary0000656: Not possible to limit permissions properly
DescriptionHi,


I tried to create a limited webui. However it does not seem possible to configure it to limit it for 1 client.

I can limit the permissions so only 1 client can be restored, but whatever I try all jobs, clients, resources etc are shown.

Probably this is the list command. The list command should limit to show only stuff related to the Job and Client ACL's.

I don't understand why this is not the case, many other programs work like that :(

It limits the otherwise great app severly since we want to give other users permissons to login, but they should not see other clients information :(

Example console:

# status, run, .status, restore, list, help, .jobs, .clients, .filesets, .pools, .storage, .defaults, .backups}
Profile {
  Name = kreative
  CommandACL = cancel, messages, rerun, restore, run, rerun, show, status, version, .api, list, jobs, .bvfs_*
  Job ACL = RestoreFiles, backup-vps52371
  Schedule ACL = *all*
  Catalog ACL = *all*
  Pool ACL = localserver, *vps52371*
  Storage ACL = localserver, *vps52371*
  Client ACL = vps52371
  FileSet ACL = *all*
  Where ACL = *all*
}

So when I remove the list, I can no longer use the webui at all to do restores.

With the list enabled way to much info is shown about resources the client should not have access to.


TagsNo tags attached.

Relationships

duplicate of 0000628 closed output of list command not restricted for own jobs/clients on restricted consoles with ACLs 

Activities

mvwieringen

mvwieringen

2016-05-09 18:55

developer   ~0002261

Please search first to see if you are not entering an duplicate. If you find
this such a problem there is also the possibility to sponsor the development
of this feature. You seem to earn money with our product so maybe we can
also ask you to share some of that with us to develop the wanted feature
via funded development. Try sales@bareos.com

Issue History

Date Modified Username Field Change
2016-05-09 13:10 hostedpower New Issue
2016-05-09 18:52 mvwieringen Relationship added duplicate of 0000628
2016-05-09 18:55 mvwieringen Note Added: 0002261
2016-05-09 18:55 mvwieringen Status new => feedback
2016-05-16 10:51 mvwieringen Status feedback => closed
2016-05-16 10:51 mvwieringen Resolution open => duplicate