Uploaded image for project: 'Dev - Nexus Repo'
  1. Dev - Nexus Repo
  2. NEXUS-24395

The "advanced search" option shows up for users without "nx-search-read", clicking it gives authorization prompt

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: New
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 3.24.0
    • Fix Version/s: None
    • Component/s: Search, Security
    • Labels:
    • Notability:
      3

      Description

      Create role with the following privileges:

      • nx-repository-view---read
      • nx-repository-view---browse

      Assign that role to a user, and log into Nexus Repo. Browse into a repository.

      In the upper right corner of the browse view there will be an "advanced search..." link. Clicking it gives an authorization prompt. This is not a good user experience, the user is already logged in.

      Expected: The link should be disabled if the user does not have search privileges.

      Workaround: Grant the user the nx-search-read privilege

        Attachments

          Activity

            People

            Assignee:
            Unassigned
            Reporter:
            rseddon Rich Seddon
            Last Updated By:
            Rich Seddon
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

              Dates

              Created:
              Updated:
              Date of First Response:

                tigCommentSecurity.panel-title