[BUG] Cluster member role user should not be able to delete node on Harvester Hosts page on Rancher managed Harvester #7255
Labels
area/rancher
Rancher related including internal and external
area/ui
Harvester UI
area/ui-extension
Harvester UI extension for managed and standalone Harvester
kind/bug
Issues that are defects reported by users or that we know have reached a real release
reproduce/always
Reproducible 100% of the time
severity/2
Function working but has a major issue w/o workaround (a major incident with significant impact)
Milestone
Describe the bug
When access Harvester v1.3.2 from Rancher virtualization management. (UI extension v1.0.2)
And create a Rancher standard user
project-member
Set the
Cluster Member
roleAnd set the
Project Member
role to thedefault project
When we login Rancher with
project-member
user to access HarvesterOn the Hosts page, the
Cluster Member
role user still can delete the nodeVideo clip reference
vokoscreenNG-2024-12-25_18-37-22.mp4
To Reproduce
Steps to reproduce the behavior:
project-member
in Rancher user management pageCluster Member
role toproject-member
Project Member
role to theproject-member
project-member
userExpected behavior
From the
Cluster Member
role description indicateFor security concern, cluster member role user should not be able to delete node on Harvester Hosts page.
Support bundle
supportbundle_50777f72-4a54-4f12-bd0f-aee3c949498a_2024-12-25T10-46-44Z.zip
Environment
The text was updated successfully, but these errors were encountered: