Project

General

Profile

action #18594

[tools][sprint 201712.1][bonus] Worker page is accessible without logging in

Added by szarate over 4 years ago. Updated almost 4 years ago.

Status:
Resolved
Priority:
Low
Assignee:
Category:
Feature requests
Target version:
Start date:
2017-04-13
Due date:
% Done:

0%

Estimated time:
Difficulty:

Description

If an unauthenticated user tries to navigate to one of the worker details page, he can see all the details.

At least he can't modify any of the jobs, but still, while it's not a security issue, i don't think that it should be available for the public, or at least not under /admin (in case we want to allow the public to access this page)

https://openqa.suse.de/admin/workers/141

History

#1 Updated by okurz over 4 years ago

We recently changed the behaviour to make more pages accessible to non-admin users. I don't think that it is a problem to have the page available under "/admin/" because "admin" says it's intended for administration, not that you need to be an admin.

#2 Updated by coolo about 4 years ago

  • Target version set to Ready

indeed - the JOBTOKEN might be a 'leak' though.

Hiding it for non-admins sounds like a nice entrance level issue though

#3 Updated by mitiao almost 4 years ago

  • Assignee set to mitiao

#4 Updated by mitiao almost 4 years ago

  • Status changed from New to In Progress
  • Target version changed from Ready to Current Sprint

first try seems a wrong direction to change worker route with auth...
focus on 'hiding'...

#5 Updated by szarate almost 4 years ago

  • Subject changed from Worker page is accessible without logging in to [tools][bonus] Worker page is accessible without logging in

#6 Updated by okurz almost 4 years ago

wait. I remember that originally mkittler developed based on my request that these pages are accessible so that anyone can check read-only the status of workers. Hiding the page completely should not be the way to go.

#7 Updated by coolo almost 4 years ago

just for the record: we're talking about hiding details on the page - not the page itself.

#8 Updated by mitiao almost 4 years ago

  • Status changed from In Progress to Resolved

PR merged

#9 Updated by szarate almost 4 years ago

  • Subject changed from [tools][bonus] Worker page is accessible without logging in to [tools][sprint 201712.1][bonus] Worker page is accessible without logging in
  • Target version changed from Current Sprint to Milestone 12

Also available in: Atom PDF