Read-only user can delete/move messages through hawtio
Issue
- In A-MQ 6.2.1R1 (as well as in AMQ 6.2.1R0 and likely in some previous versions), read-only users having the profile Monitor can delete and move messages from queues using the hawtio console.
- Created a
read-only-user, following the manual
Expectation was that logging into the web-console with usermonitorgivesread-onlyaccess to the broker configuration. However the user is still able to modify pretty much everything from the configuration of the OSGi runtime upwards. - Entry in
etc/user.properties:
- Created a
admin=admin,admin,manager,viewer,Operator, Maintainer, Deployer, Auditor, Administrator, SuperUser
monitor=monitor,Monitor
Environment
- Hawt.io
- Red Hat JBoss A-MQ
- 6.2.1 (GA, R1, R2, R3, R4)
- 6.2.0
- Red Hat JBoss Fuse
- 6.2.1 (GA, R1, R2, R3, R4)
- 6.2.0
- Red Hat JBoss A-MQ
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.