Story #8160
closed
as a user with 'auth.change_group' permission i can POST /pulp/api/v3/groups/3/users/
Status:
CLOSED - CURRENTRELEASE
Description
Looks like pulpcore 3.10.0.dev is not providing a default access policy for /pulp/api/v3/groups/<id>/users/
and as a result non-admin users can't modify users in a group using that URL.
- Copied from Story #8159: as a user with 'auth.view_group' permission i can GET /pulp/api/v3/groups/ added
- Sprint/Milestone set to 3.10.0
- Status changed from NEW to ASSIGNED
- Assignee set to mdellweg
- Tracker changed from Issue to Story
- Subject changed from user with 'auth.change_group' permission receives 403 on POST /pulp/api/v3/groups/3/users/ to as a user with 'auth.change_group' permission i can POST /pulp/api/v3/groups/3/users/
- % Done set to 0
- Severity deleted (
2. Medium)
- Triaged deleted (
No)
- Status changed from ASSIGNED to POST
- Status changed from POST to MODIFIED
- % Done changed from 0 to 100
- Status changed from MODIFIED to CLOSED - CURRENTRELEASE
Also available in: Atom
PDF
Add RBAC to the group users endpoint
fixes #8160 https://pulp.plan.io/issues/8160