You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@solr.apache.org by "Timothy Potter (Jira)" <ji...@apache.org> on 2021/12/02 15:46:00 UTC

[jira] [Updated] (SOLR-15825) Permission "all" should include "security-edit"

     [ https://issues.apache.org/jira/browse/SOLR-15825?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Timothy Potter updated SOLR-15825:
----------------------------------
    Fix Version/s: 8.11.1

> Permission "all" should include "security-edit"
> -----------------------------------------------
>
>                 Key: SOLR-15825
>                 URL: https://issues.apache.org/jira/browse/SOLR-15825
>             Project: Solr
>          Issue Type: Bug
>      Security Level: Public(Default Security Level. Issues are Public) 
>          Components: Admin UI, Authorization, Security UI
>    Affects Versions: 8.11
>            Reporter: Isabelle Giguere
>            Assignee: Timothy Potter
>            Priority: Minor
>             Fix For: 8.11.1
>
>         Attachments: security.json
>
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> With basic authentication and rule-based authorization, a user with permission "all" does not have access to the Security panel in the UI.
> Refer to the security.json attached. (credentials: admin/admin)
> The UI displays message : "You do not have permission to view the security panel."
> Workaround:  add permissions "security-edit" and "security-read" to the role (before "all").
> According to [~thelabdude], this is an issue in the UI only:
> {quote}
> this is a bug in the security UI only (not the backend),
> specifically right here:
> https://urldefense.com/v3/__https://github.com/apache/solr/blob/main/solr/webapp/web/js/angular/controllers/security.js*L344__;Iw!!Obbck6kTJA!L1x2jPaH5Hj7OSGuRO9kR5aHJK0h4ekxPfpNGckK9JglMRyaomgDN8ikSeW5f96k$ .
> {quote}



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscribe@solr.apache.org
For additional commands, e-mail: issues-help@solr.apache.org