Multi-tenancy issue!!!

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Multi-tenancy issue!!!

Post by BanditBBS »

I was just giving a demo in join.me to a customer and I masqueraded as her. Everything was fine until I clicked on the "Scheduled Downtime" link. It shows everything for all customers!

Can someone else verify this is not just something screwy in my environment.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
rkennedy
Posts: 6579
Joined: Mon Oct 05, 2015 11:45 am

Re: Multi-tenancy issue!!!

Post by rkennedy »

Was she an admin, or user - and, what privileges does she have enabled?

A screenshot of her 'Edit User' page will work to answer this. I'll try to replicate it on my end.

Also - what version of XI are you on currently?
Former Nagios Employee
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Re: Multi-tenancy issue!!!

Post by BanditBBS »

Capture.PNG
XI 5.2.1
You do not have the required permissions to view the files attached to this post.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
rkennedy
Posts: 6579
Joined: Mon Oct 05, 2015 11:45 am

Re: Multi-tenancy issue!!!

Post by rkennedy »

I can confirm, that with those privileges a user can see all OTHER scheduled downtime. When they try to schedule host downtime, it will only allow them to host / services they have access to.

Is this what you were referring to?
Former Nagios Employee
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Re: Multi-tenancy issue!!!

Post by BanditBBS »

Yeah, they shouldn't be able to see the other downtimes. They don't have permissions to see those items anywhere else within Nagios except on that downtime page.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
User avatar
lmiltchev
Bugs find me
Posts: 13589
Joined: Mon May 23, 2011 12:15 pm

Re: Multi-tenancy issue!!!

Post by lmiltchev »

I was also able to recreate the issue, and I believe this is a bug. I filed an internal bug report (TASK ID 7876).
Be sure to check out our Knowledgebase for helpful articles and solutions!
Locked