Skip to content

[Fleet] Add missing privilege callout in Integrations Policies table#195429

Merged
criamico merged 1 commit intoelastic:mainfrom
criamico:191800_rbac_fix_osquery
Oct 9, 2024
Merged

[Fleet] Add missing privilege callout in Integrations Policies table#195429
criamico merged 1 commit intoelastic:mainfrom
criamico:191800_rbac_fix_osquery

Conversation

@criamico
Copy link
Copy Markdown
Member

@criamico criamico commented Oct 8, 2024

Fixes #191800

Summary

Add missing privilege callout in Integrations Policies table.
Currently the route app/integrations/detail/{pkgName}-{version}/policies is available even though the policies tab is not visible with limited privileges.

Testing

  • Install osquery_manager
  • Enable rbac feature flag
  • Create role with privileges
    Screenshot 2024-10-08 at 16 24 46
  • Log in with user with the above role
  • Navigate to app/integrations/detail/osquery_manager-1.14.0/policies
  • Verify that a limited privileges callout is displayed
    Screenshot 2024-10-08 at 16 12 23

@criamico criamico self-assigned this Oct 8, 2024
@criamico criamico added Team:Fleet Team label for Observability Data Collection Fleet team release_note:skip Skip the PR/issue when compiling release notes v8.16.0 backport:version Backport to applied version labels labels Oct 8, 2024
@criamico criamico marked this pull request as ready for review October 8, 2024 14:32
@criamico criamico requested a review from a team as a code owner October 8, 2024 14:32
@elasticmachine
Copy link
Copy Markdown
Contributor

Pinging @elastic/fleet (Team:Fleet)

Copy link
Copy Markdown
Member

@nchaulet nchaulet left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀

@elasticmachine
Copy link
Copy Markdown
Contributor

💛 Build succeeded, but was flaky

Failed CI Steps

Test Failures

  • [job] [logs] Fleet Cypress Tests #4 / View agents list Agent status filter should filter on healthy (16 result)

Metrics [docs]

Async chunks

Total size of all lazy-loaded chunks that will be downloaded as the user navigates the app

id before after diff
fleet 1.7MB 1.7MB +127.0B

cc @criamico

@criamico criamico merged commit c3c587b into elastic:main Oct 9, 2024
@kibanamachine
Copy link
Copy Markdown
Contributor

Starting backport for target branches: 8.x

https://github.com/elastic/kibana/actions/runs/11249945368

kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Oct 9, 2024
…lastic#195429)

Fixes elastic#191800

## Summary
Add missing privilege callout in Integrations Policies table.
Currently the route
`app/integrations/detail/{pkgName}-{version}/policies` is available even
though the policies tab is not visible with limited privileges.

### Testing
- Install `osquery_manager`
- Enable rbac feature flag
- Create role with privileges
![Screenshot 2024-10-08 at 16 24
46](https://github.com/user-attachments/assets/774de651-ac91-4365-9151-2df18efc811c)
- Log in with user with the above role
- Navigate to `app/integrations/detail/osquery_manager-1.14.0/policies`
- Verify that a limited privileges callout is displayed
![Screenshot 2024-10-08 at 16 12
23](https://github.com/user-attachments/assets/4498cbc1-243b-4fa9-a028-8899670f8e14)

(cherry picked from commit c3c587b)
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 All backports created successfully

Status Branch Result
8.x

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

@criamico criamico deleted the 191800_rbac_fix_osquery branch October 9, 2024 07:30
kibanamachine added a commit that referenced this pull request Oct 9, 2024
…table (#195429) (#195534)

# Backport

This will backport the following commits from `main` to `8.x`:
- [[Fleet] Add missing privilege callout in Integrations Policies table
(#195429)](#195429)

<!--- Backport version: 9.4.3 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sqren/backport)

<!--BACKPORT [{"author":{"name":"Cristina
Amico","email":"criamico@users.noreply.github.com"},"sourceCommit":{"committedDate":"2024-10-09T07:06:56Z","message":"[Fleet]
Add missing privilege callout in Integrations Policies table
(#195429)\n\nFixes
https://github.com/elastic/kibana/issues/191800\r\n\r\n## Summary\r\nAdd
missing privilege callout in Integrations Policies table. \r\nCurrently
the route\r\n`app/integrations/detail/{pkgName}-{version}/policies` is
available even\r\nthough the policies tab is not visible with limited
privileges.\r\n\r\n### Testing \r\n- Install `osquery_manager`\r\n-
Enable rbac feature flag\r\n- Create role with
privileges\r\n![Screenshot 2024-10-08 at 16
24\r\n46](https://github.com/user-attachments/assets/774de651-ac91-4365-9151-2df18efc811c)\r\n-
Log in with user with the above role\r\n- Navigate to
`app/integrations/detail/osquery_manager-1.14.0/policies`\r\n- Verify
that a limited privileges callout is displayed\r\n![Screenshot
2024-10-08 at 16
12\r\n23](https://github.com/user-attachments/assets/4498cbc1-243b-4fa9-a028-8899670f8e14)","sha":"c3c587bc50816ce570d442b805fe63cb8faee8cc","branchLabelMapping":{"^v9.0.0$":"main","^v8.16.0$":"8.x","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:skip","Team:Fleet","v9.0.0","v8.16.0","backport:version"],"title":"[Fleet]
Add missing privilege callout in Integrations Policies
table","number":195429,"url":"https://github.com/elastic/kibana/pull/195429","mergeCommit":{"message":"[Fleet]
Add missing privilege callout in Integrations Policies table
(#195429)\n\nFixes
https://github.com/elastic/kibana/issues/191800\r\n\r\n## Summary\r\nAdd
missing privilege callout in Integrations Policies table. \r\nCurrently
the route\r\n`app/integrations/detail/{pkgName}-{version}/policies` is
available even\r\nthough the policies tab is not visible with limited
privileges.\r\n\r\n### Testing \r\n- Install `osquery_manager`\r\n-
Enable rbac feature flag\r\n- Create role with
privileges\r\n![Screenshot 2024-10-08 at 16
24\r\n46](https://github.com/user-attachments/assets/774de651-ac91-4365-9151-2df18efc811c)\r\n-
Log in with user with the above role\r\n- Navigate to
`app/integrations/detail/osquery_manager-1.14.0/policies`\r\n- Verify
that a limited privileges callout is displayed\r\n![Screenshot
2024-10-08 at 16
12\r\n23](https://github.com/user-attachments/assets/4498cbc1-243b-4fa9-a028-8899670f8e14)","sha":"c3c587bc50816ce570d442b805fe63cb8faee8cc"}},"sourceBranch":"main","suggestedTargetBranches":["8.x"],"targetPullRequestStates":[{"branch":"main","label":"v9.0.0","branchLabelMappingKey":"^v9.0.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/195429","number":195429,"mergeCommit":{"message":"[Fleet]
Add missing privilege callout in Integrations Policies table
(#195429)\n\nFixes
https://github.com/elastic/kibana/issues/191800\r\n\r\n## Summary\r\nAdd
missing privilege callout in Integrations Policies table. \r\nCurrently
the route\r\n`app/integrations/detail/{pkgName}-{version}/policies` is
available even\r\nthough the policies tab is not visible with limited
privileges.\r\n\r\n### Testing \r\n- Install `osquery_manager`\r\n-
Enable rbac feature flag\r\n- Create role with
privileges\r\n![Screenshot 2024-10-08 at 16
24\r\n46](https://github.com/user-attachments/assets/774de651-ac91-4365-9151-2df18efc811c)\r\n-
Log in with user with the above role\r\n- Navigate to
`app/integrations/detail/osquery_manager-1.14.0/policies`\r\n- Verify
that a limited privileges callout is displayed\r\n![Screenshot
2024-10-08 at 16
12\r\n23](https://github.com/user-attachments/assets/4498cbc1-243b-4fa9-a028-8899670f8e14)","sha":"c3c587bc50816ce570d442b805fe63cb8faee8cc"}},{"branch":"8.x","label":"v8.16.0","branchLabelMappingKey":"^v8.16.0$","isSourceBranch":false,"state":"NOT_CREATED"}]}]
BACKPORT-->

Co-authored-by: Cristina Amico <criamico@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport:version Backport to applied version labels release_note:skip Skip the PR/issue when compiling release notes Team:Fleet Team label for Observability Data Collection Fleet team v8.16.0 v9.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feet] Manage Integration link under Osquery Tab is navigating to empty Integration Policies page instead of showing Permissions Required error message.

4 participants