vladimirpetrov opened a new issue #352:
URL: https://github.com/apache/cloudstack-primate/issues/352


   **Describe the bug**
   Even when logged in as read-only admin (with allowed only list* actions in 
the role), you're still able to access VM consoles (VMs, system VMs, virtual 
router VMs ....) which might be dangerous.
   
   **To Reproduce**
   Steps to reproduce the behavior:
   1. Login as read-only admin user (admin role with only list* actions 
allowed).
   2. Go to some VM and click on 'View console' - you're able to see and even 
interact with all the consoles.
   
   **Expected behavior**
   I think read-only admin should not be allowed to interact with the consoles.
   
   **Screenshots**
   
![image](https://user-images.githubusercontent.com/12384665/82552204-5a2da180-9b6a-11ea-8514-df787116e812.png)
   
   **Desktop (please complete the following information):**
    - OS: Ubuntu 18.04 LTS
    - Browser: Chrome
    - Version: 83.0.4103.61 (Official Build) (64-bit)
   
   **Additional context**
   None.
   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Reply via email to