Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-11631

Going directly to Bamboo's configureGlobalPermissions.action erases all permissions

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Medium
    • 4.1
    • None
    • None

    Description

      Create a user and give them access to use restricted admin in Bamboo. As that user go directly to the path:

      /builds/build/admin/configureGlobalPermissions.action

      If you refresh the page or go to the view page, you won't have any permissions to do that because they will have been erased.
      Effect: Data loss (in the form of who can do what), DoS (people can't use Bamboo), support costs (fixing it will be a PITA for our supporters).

      This was first picked up in OnDemand, but I think it is a bamboo + webwork problem. Tim Moore was able to reproduce this on a bamboo 4 standalone instance.

      Attachments

        Issue Links

          Activity

            People

              pbruski Przemek Bruski
              asrinivasan Ashwin Srinivasan (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: