OpenMetadata icon indicating copy to clipboard operation
OpenMetadata copied to clipboard

Issues with Role & Policies related to Resource: User

Open hoangdh5 opened this issue 2 years ago • 4 comments

cc @chirag-madlani as the conversation on Slack.

Affected module backend - Role & Policies

Describe the bug Create a new policy with only User, Team, Role resources image

Create new Role and link with new policy was created.

Expected new role should have permission to create, edit, and update User, Team, and Role. But only Teams and Role can edit. User still not allow to create or edit. image

hoangdh5 avatar Oct 03 '23 06:10 hoangdh5

For Roles, with the same policy. I can delete or add but can not change existing Role For Admins, only view. can not change or edit.

hoangdh5 avatar Oct 03 '23 06:10 hoangdh5

Please review all other resources to make sure when we create a single policy rule for each resource, it can work like we were set up on allow/ not allow config. Thanks team!

hoangdh5 avatar Oct 03 '23 07:10 hoangdh5

Please review all other resources to make sure when we create a single policy rule for each resource, it can work like we were set up on allow/ not allow config. Thanks team!

@hoangdh5, you can help the team by doing this review, and feel free to add details of problems you find into this same issue.

sureshms avatar Oct 19 '23 19:10 sureshms

Hello @hoangdh5, some resource requires admin permissions to perform operations like edit, delete and create. even some resources are only visible to the admin only. therefore policy will not take effect in those resources.

Sachin-chaurasiya avatar Jan 25 '24 14:01 Sachin-chaurasiya

@open-metadata/ui here i think we can use permission for creation of Users as well

mohityadav766 avatar Mar 31 '25 06:03 mohityadav766

@open-metadata/ui https://github.com/open-metadata/OpenMetadata/pull/20520 ths PR allows users with edit codition to run validations for policies but we anyway have support for user, roles and policies to be controlled via user permissions

mohityadav766 avatar Mar 31 '25 07:03 mohityadav766