Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Fleet]: User gets forbidden error under Agents tab for custom user with Agent policies None. #191957

Closed
amolnater-qasource opened this issue Sep 3, 2024 · 5 comments · Fixed by #193070
Labels
bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. QA:Validated Issue has been validated by QA Team:Fleet Team label for Observability Data Collection Fleet team

Comments

@amolnater-qasource
Copy link

amolnater-qasource commented Sep 3, 2024

Kibana Build details:

VERSION: 8.16.0 SNAPSHOT
BUILD: 77913
COMMIT: f2aba4624160124344e98dac19d5eefd83fa79ce

Role:

Integrations: All
Fleet: Read
Agents: All
Agent policies: None
Settings: Read

Image

  • Also reproducible for Settings: All.

Preconditions:

  1. 8.16.0-SNAPSHOT Kibana cloud environment should be available.
  2. New User should be created with above defined role.

Steps to reproduce:

  1. Login with the above user.
  2. Navigate to Agents tab.
  3. Observe Forbidden error is displayed under Agents tab.

Expected Result:
User shouldn't get forbidden error under Agents tab for custom user with Agent policies None.

Screen Recording:

Settings.-.Fleet.-.Elastic.-.Google.Chrome.2024-09-03.15-33-34.mp4

Feature:
https://github.com/elastic/ingest-dev/issues/2903

@amolnater-qasource amolnater-qasource added bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. Team:Fleet Team label for Observability Data Collection Fleet team labels Sep 3, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/fleet (Team:Fleet)

@amolnater-qasource
Copy link
Author

@muskangulati-qasource Please review.

@amolnater-qasource amolnater-qasource changed the title [Fleet]: User gets forbidden error under Agents tab for custom user with Agent policies None and Settings: Read. [Fleet]: User gets forbidden error under Agents tab for custom user with Agent policies None. Sep 3, 2024
@muskangulati-qasource
Copy link

Secondary review on this ticket it Done!

@nchaulet
Copy link
Member

Seems a bug introduced by now using the _bulk_get API instead of the retrieving all agent policies in #191661

@amolnater-qasource
Copy link
Author

Hi Team,

We have revalidated this issue on latest 8.16.0 SNAPSHOT and found it fixed now.

Observations:

  • User doesn't get forbidden error under Agents tab for custom user with Agent policies None.

Build details:
VERSION: 8.16.0 SNAPSHOT
BUILD: 78885
COMMIT: 4e4107b

Screen Recording

Agents.-.Fleet.-.Elastic.-.Google.Chrome.2024-10-08.14-08-13.mp4

Hence, we are marking this issue as QA:Validated.

Thanks!!

@amolnater-qasource amolnater-qasource added QA:Validated Issue has been validated by QA and removed QA:Ready for Testing Code is merged and ready for QA to validate labels Oct 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. QA:Validated Issue has been validated by QA Team:Fleet Team label for Observability Data Collection Fleet team
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants