[JIRA] (JENKINS-61902) "authenticated" group doesn't work with Authorize Project plugin

2 views
Skip to first unread message

devld@ikedam.jp (JIRA)

unread,
Apr 18, 2020, 11:56:03 PM4/18/20
to jenkinsc...@googlegroups.com
ikedam updated an issue
 
Jenkins / Bug JENKINS-61902
"authenticated" group doesn't work with Authorize Project plugin
Change By: ikedam
Summary: Slave roles not respected "authenticated" group doesn't work with Authorize Project plugin
Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.13.12#713012-sha1:6e07c38)
Atlassian logo

devld@ikedam.jp (JIRA)

unread,
Apr 19, 2020, 12:24:03 AM4/19/20
to jenkinsc...@googlegroups.com
ikedam assigned an issue to akostadinov
 

Groups that a user is assigned depends on the security realm you use.
I suppose the security realm you use doesn't assign "authenticated" group to the user when authorize-project queries the user.

I could not reproduce the issue with built-in "Jenkins’ own user database" as it always assigns "authenticated" group to the user.

I don't think it's a bug of the security realm as the query by the authorize-project plugin is independent from user's login process. The security realm can't say to authorized-project plugin whether the user is authenticated.
I suppose "authenticated" group is always assigned for Web UI operations as Jenkins knows the user is actually authenticated.

I won't fix this issue as managing actual permissions is out of the domain of authorize-project and managing permissions carelessly can easily cause security issues.

Please instead create a new group for all Jenkins users and assign the role to that group.

Change By: ikedam
Assignee: ikedam akostadinov
Reply all
Reply to author
Forward
0 new messages