wi3dzma opened a new issue, #14014:
URL: https://github.com/apache/cloudstack/issues/14014

   ### problem
   
   If account/user is added to the project with custom role (even if role 
permisions are "allow *") user can login to CS successfully but switching to 
project view will fail and generate multiple errors: "
   
   ```
   The given command 'listApis' either does not exist, is not available for 
user. Unable to proceed. Please contact your administrator." 
   The given command 'listZones' either does not exist, is not available for 
user. Unable to proceed. Please contact your administrator.
   The given command 'listCapabilities' either does not exist, is not available 
for user. Unable to proceed. Please contact your administrator.
   ...
   ```
   
   <img width="386" height="134" alt="Image" 
src="https://github.com/user-attachments/assets/a4fa1a9d-4245-4401-b7f3-4114e973828b";
 />
   
   On browser console indeed you can see that request:
   ` /client/api/?command=listApis&response=json&sessionkey=xxx&projectid=xxx`
   returns:
   
`{"listapisresponse":{"uuidList":[],"errorcode":401,"cserrorcode":9999,"errortext":"The
 given command 'listApis' either does not exist, is not available for user."}}
   `
   If user is added to the project with Admin or Regular Type without any 
project role, switching to project view works correctly.
   
   Switching to project view using custom Project Roles in 4.22.1.0 works 
correctly.
   Also using UI ver. 4.22.1.1 and Api ver: 4.22.1.0 works correctly.
   
   No additional logs available in:
   ```
   cloudstack/management/apilog.log
   cloudstack/management/management-server.log
   ```
   
   ### versions
   
   ACS: 4.22.1.1
   
   
   
   ### The steps to reproduce the bug
   
   1. Create new project "Test"
   2. Create Project Role with "allow *" permission
   3. Add non-admin user to project with that Project Role 
   4. Switch to Project View  of "Test" project
   
   
   ### What to do about it?
   
   Please track the root cause and fix the bug


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to