Non-admin users can mount and unmount special fs for Ready nodes

Bug #1812217 reported by Björn Tillenius
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
MAAS
Triaged
Medium
Unassigned

Bug Description

This is with MAAS 2.5.1-7489-g2f25a2cc0-0ubuntu1~18.04.1 with RBAC enabled.

I have a user that has the User role on a resource pool.

That use can use the 'machine mount-special' to mount a tmpfs
on a machine that is in the Ready state without any owner.

Without RBAC enabled, non-admin users aren't allowed to do this.

Tags: api rbac
tags: added: api rbac
Changed in maas:
status: New → Triaged
importance: Undecided → High
milestone: none → 2.5.1
Changed in maas:
milestone: 2.5.1 → 2.5.2
Changed in maas:
milestone: 2.5.2 → 2.5.3
Changed in maas:
milestone: 2.5.3 → 2.6.0beta2
Changed in maas:
milestone: 2.6.0beta2 → 2.6.0rc1
Changed in maas:
milestone: 2.6.0rc1 → 2.6.0rc2
Changed in maas:
milestone: 2.6.0rc2 → 2.7.0alpha1
Changed in maas:
milestone: 2.7.0b1 → 2.7.0b2
Changed in maas:
milestone: 2.7.0b2 → none
summary: - [2.5, RBAC, API] Non-admin users can mount and unmount special fs for
- Ready nodes
+ Non-admin users can mount and unmount special fs for Ready nodes
Changed in maas:
importance: High → Medium
milestone: none → 3.5.0
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.