API Login ACL response values differ from CLI

Bug #1629089 reported by Jeff Pihach
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Canonical Juju
Fix Released
High
Tim Penhey

Bug Description

When bootstrapping with a defined external identity service and then running:

juju grant everyone@external addmodel

When a user logs in via USSO to the controller over the API the login response for the user-info does not include the proper values for the controller access.

controller-access: ""
model-access: ""

At a minimum here I would expect the `controller-access` field to have "addmodel"

Tags: ateam
Revision history for this message
Richard Harding (rharding) wrote :

So this breaks the GUI add-model flow for users since it can't tell when to enable/disable the functionality.

Changed in juju:
status: New → Triaged
importance: Undecided → High
assignee: nobody → Alexis Bruemmer (alexis-bruemmer)
milestone: none → 2.0.0
Revision history for this message
Jeff Pihach (hatch) wrote :

When using `juju grant <username>@external addmodel` the controller-access field has "addmodel" in it.

And when logging in as the admin@local user the controller-access field has "superuser" as expected.

Tim Penhey (thumper)
Changed in juju:
assignee: Alexis Bruemmer (alexis-bruemmer) → Tim Penhey (thumper)
status: Triaged → In Progress
tags: added: ateam
Changed in juju:
status: In Progress → Fix Committed
Curtis Hovey (sinzui)
Changed in juju:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.