-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Response Ops] Rules navigation appears if user has access to Actions and Connectors
but no rule types
#158256
Comments
Pinging @elastic/response-ops (Team:ResponseOps) |
It looks like the capabilities that result from such a role configuration include which is associated to the Rules app in the ManagementSection and thus makes the page visible: @mdefazio should we remove that capability from |
Likely need others input here, but if I'm understanding this... So what happens when access to Stack Rules is allowed? Not saying it should, but does this enable Actions and Connectors via While I should likely know this, when am I using Actions and Connectors outside of Rules or Cases? There was always the intention, but are they used elsewhere? Looking at the screenshots, should this config only effect And since we're here...shouldn't Maintenance Windows be tied closer to the triggersActions? Since you would be stopping actions by creating a maintenance window |
It does, and when inspecting the role in http calls only
It does not, the only enabled feature is To my (still very limited) understanding, the mapping between privileges and capabilities in this case seems to be:
|
…rule types requests (#171417) Closes #158256, #155394 ## Summary - Hides the Logs tab in the Stack Management > Rules page when the user lacks the necessary permissions to avoid error messages (as shown in #158256) - Switches old `useLoadRuleTypes` hook usages to the new `useLoadRuleTypesQuery` hook - Assigns a staleTime to the rule types query to avoid duplicated requests (as shown in #155394) --------- Co-authored-by: Xavier Mouligneau <xavier.mouligneau@elastic.co>
When we have a role that gives a user access to



Actions and Connectors
but no alerting rule types, the user is still able to seeRules
in theStack Management
navigation. Going to the page will showNo access
but I believe that this menu item shouldn't show up at all for this role.The text was updated successfully, but these errors were encountered: