New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[JENKINS-68208] "Create a job" button is not hidden to users lacking permission. #6689
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This change is incorrect.
Authorization strategies like Project-based Matrix Authorization give users fine-grained control over who is allowed to create items where. To create an item in a folder, you only need permission to create an item inside that folder, not on the root level. That case would be broken by this change.
The problem here is probably related to the view owner being the user (for "My Views"), and a user has full permissions on itself to freely configure all properties. This seems to be a bad interaction not considered by the Groovy view, but the fix would be different from this change.
Co-authored-by: Daniel Beck <1831569+daniel-beck@users.noreply.github.com>
Thanks for your suggestion. |
This PR is now ready for merge. We will merge it after ~24 hours if there is no negative feedback. |
See JENKINS-68208.
Before: (User without Job/Create permission can see the button)
After: (User without Job/Create permission can't see the button now)
Proposed changelog entries
Proposed upgrade guidelines
N/A
Submitter checklist
Proposed changelog entries
section only if there are breaking changes or other changes which may require extra steps from users during the upgrade@Restricted
or have@since TODO
Javadoc, as appropriate.Desired reviewers
@mention
Maintainer checklist
Before the changes are marked as
ready-for-merge
:Proposed changelog entries
are accurate, human-readable, and in the imperative moodupgrade-guide-needed
label is set and there is aProposed upgrade guidelines
section in the PR title. (example)lts-candidate
to be considered (see query).