Read-only user can delete/move messages through hawtio

Solution Verified - Updated -

Issue

  • In A-MQ 6.2.1R1 (as well as in AMQ 6.2.1R0 and likely in some previous versions), read-only users having the profile Monitor can delete and move messages from queues using the hawtio console.
    • Created a read-only-user, following the manual
      Expectation was that logging into the web-console with user monitor gives read-only access to the broker configuration. However the user is still able to modify pretty much everything from the configuration of the OSGi runtime upwards.
    • Entry in etc/user.properties:
admin=admin,admin,manager,viewer,Operator, Maintainer, Deployer, Auditor, Administrator, SuperUser
monitor=monitor,Monitor

Environment

  • Hawt.io
    • Red Hat JBoss A-MQ
      • 6.2.1 (GA, R1, R2, R3, R4)
      • 6.2.0
    • Red Hat JBoss Fuse
      • 6.2.1 (GA, R1, R2, R3, R4)
      • 6.2.0

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content