PaulAngus opened a new issue #475:
URL: https://github.com/apache/cloudstack-primate/issues/475


   **Describe the bug**
   
   Many screens show Account and Domain to non-root admins when they should not.
   In some cases it is purely superfluous (the user would know what account 
they were in)
   In other cases (ie templates which can come from other accounts) it causes 
security data leakage.
   
   **To Reproduce**
   Steps to reproduce the behavior:
   
   Log in as a non-admin user.
   1. Go to one of the following screens:
   Compute
   - Kubernetes
   - Instance Groups
   - SSH Key Pairs
   - Affinity Groups
   Volumes
   - Snapshots
   - VM Snapshots
   - Backups
   Networks
   - Guest Networks
   - VPC
   - Security Groups
   - Public IP addresses
   - VPN Customer Gateway
   Images
   - Templates
   - ISOs
   Projects
   
   See that 'account' and or 'domain' are visible
   
   **Expected behavior**
   A clear and concise description of what you expected to happen.
   
   **Screenshots**
   If applicable, add screenshots to help explain your problem.
   
![image](https://user-images.githubusercontent.com/4810220/86149869-78d17180-baf4-11ea-826f-dbb5139b8e1d.png)
   
   **Desktop (please complete the following information):**
    - OS: [e.g. Windows, Mac, iOS, Android with device/screen details if 
applicable]
    - Browser [e.g. chrome, safari]
    - Version [e.g. 22]
   
   **Additional context**
   Add any other context about the problem here.
   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Reply via email to