[JIRA] (JENKINS-58886) Project base security matrix allows wrong group of users access

0 views
Skip to first unread message

flood@itnews-bg.com (JIRA)

unread,
Aug 11, 2019, 5:53:03 AM8/11/19
to jenkinsc...@googlegroups.com
Steve Todorov created an issue
 
Jenkins / Bug JENKINS-58886
Project base security matrix allows wrong group of users access
Issue Type: Bug Bug
Assignee: Unassigned
Attachments: image-2019-08-11-12-36-30-465.png
Components: core, ldap-plugin
Created: 2019-08-11 09:52
Environment: Jenkins 2.189
LDAP
Priority: Blocker Blocker
Reporter: Steve Todorov

We have a folder with projects inside which have `project-based security` enabled and the Inheritance Strategy is set to `Inherit from parent`. The folder's permissions are:

In the screenshot above I've added `myname-noaccess` just to illustrate the group permissions - in reality it is missing in the configuration.

The problem is that the users from the `myname-noaccess` group, although not configured anywhere, are able to see the all of projects within the folder. While trying to figure out the issue, I noticed that `myname-noaccess` users actually have the same permissions as the `myname` group and once I removed it the folder and projects inside stopped appearing for `myname-noaccess`. 

I believe there might be an issue with how the permissions are being detected - most likely there is a wildcard somewhere.

The temporary fix is to rename `myname` group to something like `myname-core`.

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)

m.winter@sap.com (JIRA)

unread,
Jan 30, 2020, 4:04:02 PM1/30/20
to jenkinsc...@googlegroups.com
Markus Winter updated an issue
Change By: Markus Winter
Component/s: matrix-auth-plugin
This message was sent by Atlassian Jira (v7.13.6#713006-sha1:cc4451f)
Atlassian logo

dbeck@cloudbees.com (JIRA)

unread,
Feb 12, 2020, 5:24:04 PM2/12/20
to jenkinsc...@googlegroups.com
Daniel Beck commented on Bug JENKINS-58886
 
Re: Project base security matrix allows wrong group of users access

Steve Todorov Is this still a problem?

My best guess is something is weird about the group memberships, and I would have affected users go to the /whoAmI URL to see what groups they're a member of.

dbeck@cloudbees.com (JIRA)

unread,
Feb 22, 2020, 7:04:04 PM2/22/20
to jenkinsc...@googlegroups.com
Daniel Beck closed an issue as Cannot Reproduce
 

Closing for now. Steve Todorov Please reopen if this is still a problem, and provide the requested information above.

(Everyone else: Please file a new issue if you experience something similar.)

Change By: Daniel Beck
Status: Open Closed
Resolution: Cannot Reproduce
Reply all
Reply to author
Forward
0 new messages