[2.5, RBAC, API] Resource pool admins can't update machine details

Bug #1811699 reported by Björn Tillenius
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
MAAS
Fix Released
High
Björn Tillenius

Bug Description

This is with MAAS 2.5.1-7489-g2f25a2cc0-0ubuntu1~18.04.1 and RBAC enabled.

If I'm authenticated as a user that has the Admin role on a resource pool,
the update command for a machine still can't be used:

  lilium:~> maas user4 machine update 6q33ak hostname=my-name
  This method is reserved for admin users.

In fact, it seems that a lot of the methods under machine is
only accessible to global admins, so we'll have to go through
each one of them and fix them.

The ones that are confirmed affected are:
  machine update
  machine power-parameters

There are also some methods under the 'machines' endpoint that have the
same problem. The bug to track that is bug 1813181.

Tags: api rbac

Related branches

tags: added: rbac
Changed in maas:
status: New → Triaged
importance: Undecided → High
milestone: none → 2.5.1
description: updated
tags: added: api
description: updated
description: updated
description: updated
description: updated
Changed in maas:
status: Triaged → In Progress
assignee: nobody → Björn Tillenius (bjornt)
description: updated
description: updated
Changed in maas:
status: In Progress → Fix Committed
Changed in maas:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.