Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-32303

Eventing : Non-admin user is able to perform Eventing crud operations

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Critical
    • 5.5.3
    • 5.5.3
    • eventing
    • None
    • Untriaged
    • Yes

    Description

      Build : 5.5.3-4038

      Steps :
      1. On 2 node cluster with one node having eventing service, install all 3 sample buckets.
      2. Create a user - testuser - and assign the Bucket Admin role & all Data service roles for beer-sample bucket to this new user.
      3. Login as testuser

      Testuser is able to create/delete/deploy/undeploy a function involving other buckets as well for which the user does not have permissions. Only a user with Full Admin permissions is supposed to be able to perform Eventing CRUD operations.

      Attachments

        Issue Links

          No reviews matched the request. Check your Options in the drop-down menu of this sections header.

          Activity

            People

              mihir.kamdar Mihir Kamdar (Inactive)
              mihir.kamdar Mihir Kamdar (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Gerrit Reviews

                  PagerDuty