Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Model Permession #42620

Closed
MQinna opened this issue May 14, 2024 · 2 comments
Closed

Model Permession #42620

MQinna opened this issue May 14, 2024 · 2 comments
Labels

Comments

@MQinna
Copy link

MQinna commented May 14, 2024

Describe the bug

Users can Edit a Model Query using Native Query editor Without Having PermessionPermission

To Reproduce

a. Create a Group with preview-only access and add a user to this group only.
b. Disable Native Query Editor for this Group.
c. Create a user with model creation access.
d. Create a model with native query enabled and add it to the analytics collection.
e. Log in as the user from the newly created group.
f. Navigate to the newly created model.
g. Attempt to edit the model query.

Expected behavior

The user from the group with preview-only access, and with the Native Query Editor restricted, should not be able to edit the model query. The system should enforce the read-only access level set for the group, preventing any modifications to the model's query.

Logs

the log will be no use case for this.

Information about your Metabase installation

Version 124.0.6367.201 (Official Build) (64-bit)
Windows 11
MySql 
0.49.8
Jar File on Ubuntu
MySql

Severity

Altering Security and access rights

Additional context

No response

@MQinna MQinna added .Needs Triage Type:Bug Product defects labels May 14, 2024
@paoliniluis
Copy link
Contributor

Hi, please check the repro steps, although the user can SEE the SQL, it doesn't mean that they can EDIT it.

I wasn´t able to reproduce

@Tony-metabase
Copy link
Contributor

The moment you press on edit you are not able to write anything in the editor and not even save

image

@paoliniluis paoliniluis closed this as not planned Won't fix, can't repro, duplicate, stale May 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants