Uploaded image for project: 'Dev - Nexus Repo'
  1. Dev - Nexus Repo
  2. NEXUS-34594

A user needs view-browse privilege to see a member repository in its group repository's Members list

    Details

    • Type: Bug
    • Status: New
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 3.41.0
    • Fix Version/s: None
    • Component/s: Security
    • Notability:
      3

      Description

      Problem description

      when checking a group repository's Member list on the group repository management page,  a user can only see a member repository's name if the user has the view-browse privilege of the member repository. If a user doesn't want to see the member repository on the browse page but wants to see its name in its group repository's Members list. The current privilege configuration can't meet the requirement. 

      Reproduce

      1.) Create a user

      2.) Create a group repository maven-public which has 2 member repositories: maven-central and maven-releases

      3.) Create a role and add the below privileges to the role: 

      nx-repository-admin-maven2-maven-public-read
      nx-repository-view-maven2-maven-releases-browse

      4.) Assign the role in 3.) to the user created in 1.)

      5.) Login with the user created in 1.) Go to Administration->Repositories->maven-public 

      check the Members list, and the repository maven-central isn't shown in the Members list (see attachment)

      6.) Add the below privileges to the role in 4.), then the user can see maven-central in the Members list, but it doesn't meet the requirement, as the user should see the repository on the browser page(/#browse/browse). 

      nx-repository-view-maven2-maven-central-browse

      Expected behavior

      To see a member repository's name in its Group repository's Members list shouldn't need view-browse privilege 

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned Unassigned
              Reporter:
              dqiu Daolong Qiu
              Last Updated By:
              Peter Lynch Peter Lynch
              Votes:
              1 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:

                  tigCommentSecurity.panel-title