Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Stack Management" menu + settings page visible for custom role that only has Dashboard read access #78229

Closed
boutcher opened this issue Sep 22, 2020 · 3 comments
Labels
Feature:Security/Spaces Platform Security - Spaces feature Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! triage_needed

Comments

@boutcher
Copy link

Kibana version: 7.9.1

Describe the bug: I've defined a role with custom space privileges, where the role only has read access to dashboards and visualizations. When looking at the menu for a user assigned to that role, you see dashboards, visualizations, and ALSO "Stack Management", which is the furthest thing from their permissions you'd expect them to see. Why is this? I've got two screenshots that show the issue below.

custom space privs

stack management on menu

@kertal kertal added Feature:Security/Spaces Platform Security - Spaces feature Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! labels Sep 23, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-security (Team:Security)

@azasypkin
Copy link
Member

Thanks for filing this issue @boutcher !

I'm pretty sure it works as "intended" (in a sense that's old known thing and that it doesn't really give any additional access to the user with such role) and we finally fixed this in 7.10 with #67791 (see this issue for the details of behavior you're observing). But I'll let @legrego to confirm and close this issue if so.

@legrego
Copy link
Member

legrego commented Sep 23, 2020

Yeah, this was a long-standing limitation of the existing privilege system. #67791 will automatically hide management sections based on your cluster and index privileges. If you don't have access to any management sections, then the management app will be hidden altogether. Hope this helps!

@legrego legrego closed this as completed Sep 23, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Security/Spaces Platform Security - Spaces feature Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! triage_needed
Projects
None yet
Development

No branches or pull requests

5 participants