all lists on lists.proxmox.com
 help / color / mirror / Atom feed
* [pdm-devel] [PATCH datacenter-manager v2 0/3] fix #6901: allow non root users to access the EVPN dashboard
@ 2025-10-17 13:02 Shan Shaji
  2025-10-17 13:02 ` [pdm-devel] [PATCH datacenter-manager v2 1/3] fix #6901: api: add explicit permission check for controllers list Shan Shaji
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Shan Shaji @ 2025-10-17 13:02 UTC (permalink / raw)
  To: pdm-devel

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain; charset=yes, Size: 1217 bytes --]

When a non-root user tried to access the EVPN section, the API was
returning a "403: permission check failed" error. To fix this, explicit
permission checks have been added for the `/zones`, `/vnets`, and
`/controllers` endpoints.

Now, every authenticated user can access these endpoints however, the user
must have at least the Resource.Audit permission under `/resource`.
Remotes are also filtered based on the user’s access. Lists will only be
fetched from remotes for which the user has at least the
`Resource.Audit` permission on `/remote/{remote_name}`.

changes since v1: thanks @stefan
patch: https://lore.proxmox.com/pdm-devel/DDKKKUCY3S4R.1FDPCH2742RY5@proxmox.com/T/#t
- Removed unused import from vnets.rs file. 

Shan Shaji (3):
  fix #6901: api: add explicit permission check for controllers list
  fix #6901: api: add explicit permission check for vnets list
  fix #6901: api: add explicit permission check for zones list

 server/src/api/sdn/controllers.rs | 30 ++++++++++++++++++++++++++----
 server/src/api/sdn/vnets.rs       | 28 +++++++++++++++++++++++++---
 server/src/api/sdn/zones.rs       | 28 +++++++++++++++++++++++++---
 3 files changed, 76 insertions(+), 10 deletions(-)

-- 
2.47.3




[-- Attachment #2: Type: text/plain, Size: 160 bytes --]

_______________________________________________
pdm-devel mailing list
pdm-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pdm-devel

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2025-10-17 13:02 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-10-17 13:02 [pdm-devel] [PATCH datacenter-manager v2 0/3] fix #6901: allow non root users to access the EVPN dashboard Shan Shaji
2025-10-17 13:02 ` [pdm-devel] [PATCH datacenter-manager v2 1/3] fix #6901: api: add explicit permission check for controllers list Shan Shaji
2025-10-17 13:02 ` [pdm-devel] [PATCH datacenter-manager v2 2/3] fix #6901: api: add explicit permission check for vnets list Shan Shaji
2025-10-17 13:02 ` [pdm-devel] [PATCH datacenter-manager v2 3/3] fix #6901: api: add explicit permission check for zones list Shan Shaji

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal