[AAA-248] Incorrect behavior in aaa-policy in aaa version 0.17.2 (Netconf-5.0.0) Created: 31/Jan/23 Updated: 31/Jan/23 |
|
| Status: | Open |
| Project: | aaa |
| Component/s: | None |
| Affects Version/s: | None |
| Fix Version/s: | None |
| Type: | Bug | Priority: | Medium |
| Reporter: | Arun Venkatesha | Assignee: | Venkatrangan Govindarajan |
| Resolution: | Unresolved | Votes: | 0 |
| Labels: | aaa-0.17.2 | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Description |
|
Using the Netconf version 5.0.0 and which includes aaa version 0.17.2. While user is assigned with a policy to perform only 'GET' operation is also able to perform 'PUT' operation. Step 1: Creation of user. curl --user admin:admin --request POST 'http://<controller IP>:8181/auth/v1/users' \ ' Step 2: Assigning role to the user curl --user admin:admin --request POST 'http://<controller_IP>:8181/auth/v1/domains/sdn/users/abc@sdn/roles' \ ' Step 3: Assigning policy to the role { ] Summary: User is assigned with authorization to perform 'GET' operation only but it is allowing to perform 'PUT' operation as well. |