[RBAC] User having no permissions for backup storages able to create a DB cluster with backup schedule using a storage location

Description

Tested on v1.2.0-rc7
STRs:
1. Remove all backupstorage permissions for a user
2. Create db cluster and add backups schedule

Actual Outome:
Success

Expected Outcome:
Backup storage should not be visible to the user.

Not sure how the UI is able to get this information if the backup storage api returns ‘enforce did not pass’


Environment

None

Attachments

1
  • 31 Oct 2024, 08:07 AM

Activity

Show:

Yusaf Awan October 31, 2024 at 8:07 AM

The user is still able to see the backup storage location name, though the user has no backup storage location permissions. Also, I am not sure if we should show the option ‘Create Backup’ if the user has no permissions for backup storage location.

Fábio Da Silva October 7, 2024 at 3:14 PM

Yusaf Awan September 30, 2024 at 10:41 AM

On demand backups get created without any error as well.

Unresolved

Details

Assignee

Reporter

Fix versions

Priority

Smart Checklist

Created September 30, 2024 at 10:00 AM
Updated November 18, 2024 at 12:45 PM