all lists on lists.proxmox.com
 help / color / mirror / Atom feed
* [pdm-devel] [PATCH datacenter-manager v2 0/2] fix #6901: add explicit permissions for PBS status and RRD endpoints
@ 2025-10-14  8:56 Shan Shaji
  2025-10-14  8:56 ` [pdm-devel] [PATCH datacenter-manager v2 1/2] fix #6901: api: add permission checks for PBS rrd endpoints Shan Shaji
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Shan Shaji @ 2025-10-14  8:56 UTC (permalink / raw)
  To: pdm-devel

If a non-root user tried to view the overview of a PBS, a 
"403: permission check failed" error was shown. Additionally, 
the RRD data for the node and datastores were not visible.

To fix the issue, explicit permission checks were added for 
the PBS RRD endpoints and the PBS status endpoint.

Ticket #6901 also reports a similar issue in the EVPN panel, 
which will be addressed in a separate patch.

Changelog
=========

since v1: Thanks @Shannon Sterz
patch:  https://lore.proxmox.com/pdm-devel/20251010151803.257519-1-s.shaji@proxmox.com/T/#t

- Updated description for both status and RRD endpoints. 
- Updated commit message.

Shan Shaji (2):
  fix #6901: api: add permission checks for PBS rrd endpoints
  fix #6901: api: remove `node` reference from templated privilege path

 server/src/api/pbs/mod.rs     |  3 ++-
 server/src/api/pbs/rrddata.rs | 11 ++++++++++-
 2 files changed, 12 insertions(+), 2 deletions(-)

-- 
2.47.3



_______________________________________________
pdm-devel mailing list
pdm-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pdm-devel


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2025-10-16 22:49 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-10-14  8:56 [pdm-devel] [PATCH datacenter-manager v2 0/2] fix #6901: add explicit permissions for PBS status and RRD endpoints Shan Shaji
2025-10-14  8:56 ` [pdm-devel] [PATCH datacenter-manager v2 1/2] fix #6901: api: add permission checks for PBS rrd endpoints Shan Shaji
2025-10-14  8:56 ` [pdm-devel] [PATCH datacenter-manager v2 2/2] fix #6901: api: remove `node` reference from templated privilege path Shan Shaji
2025-10-14  9:15 ` [pdm-devel] [PATCH datacenter-manager v2 0/2] fix #6901: add explicit permissions for PBS status and RRD endpoints Shannon Sterz
2025-10-16 22:48 ` [pdm-devel] applied: " Thomas Lamprecht

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal