winterhazel commented on PR #8978:
URL: https://github.com/apache/cloudstack/pull/8978#issuecomment-2079268907

   > @winterhazel @bernardodemarco I tried this in qa:
   > 
   > ```
   > I created a role based on the Read-Only User role.
   > I denied the role's access to listVirtualMachines, listNetworks, 
listVolumes and listTemplates APIs.
   > I created an account using the custom role.
   > I tried to log in but could not.
   > ```
   > 
   > to double check I created a "regular" Read-Only user and could log in.
   
   Hey @DaanHoogland, I reproduced your steps in QA and was able to log in. I 
created the account `t` (password is also `t`).
   
   I suppose that the user you created was `cripple`. I verified that it did 
not have access to `listZones`, which is an API users are unable to login 
without. This behavior has nothing to do with the changes here, and you can 
verify that this account is unable to login in the QA of other PRs as well.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to