Sangeeta Ravindran created AMBARI-21120:
-------------------------------------------

             Summary: Roles below Cluster Administrator should not be allowed 
to edit repositories and install stack versions
                 Key: AMBARI-21120
                 URL: https://issues.apache.org/jira/browse/AMBARI-21120
             Project: Ambari
          Issue Type: Bug
    Affects Versions: trunk
            Reporter: Sangeeta Ravindran
            Assignee: Sangeeta Ravindran
            Priority: Minor


Login as a user with a role below Cluster Administrator. For e.g. Service 
Admnistrator.
Click on Stack and Versions.

1. Try to edit a stack version that is not yet installed on the cluster.
Click on Save. The UI reloads and returns to Services Dashboard.
On the browser console, you can see a HTTP 403 because the user does not have 
the privilege to edit stack versions. 

2. Click on Install. When you click on on the popup confirming that the 
packages will be installed on all hosts, you get a popup with an error 
"Packages could not be installed. You do not have permissions to access this 
resource".
 




--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

Reply via email to