Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

All users have administrator privileges #198

Closed
Nikopol315 opened this issue Oct 11, 2016 · 6 comments
Closed

All users have administrator privileges #198

Nikopol315 opened this issue Oct 11, 2016 · 6 comments
Labels

Comments

@Nikopol315
Copy link

I'm confused, why all users have administrator privileges(every user can change a password of other users)?

It seems to be a big security leak. Isn't it?

If a user does not have an access to the project, it can easily change a password of another user, who has admin privileges. Then, it can login as a project administrator user and give the same admin privileges for the project to the any user

@Nikopol315
Copy link
Author

It's the awesome project! Nice GUI to run ansible tasks. Many thanks to the author!

But, because of this issue, I'm not able to use it in my organisation :(

@rakshazi
Copy link
Contributor

rakshazi commented Dec 7, 2016

@Nikopol315 as for 2.0.4, only user with admin rights can perfom admin actions in project, but buttons (and links) still visibly for all users.
You can test it:

  1. Create 2 users: admin (with admin rights for project) and user (without admin rights)
  2. Try to remove or edit existing project with admin user - all ok, you can do that.
  3. Try to remove or edit existing project with user user - you will see error on this actions.

@matejkramny matejkramny added the bug label Dec 9, 2016
@matejkramny
Copy link
Contributor

Thanks for reporting

@akentosh
Copy link

Any ideas on when the fixes will be merged?

@matejkramny
Copy link
Contributor

hmm soon hopefully. Haven't given much attention to this project recently unfortunately.

@twhiston
Copy link
Contributor

fixed by #405

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

5 participants