OpenCTI-Platform / opencti

Open Cyber Threat Intelligence Platform
https://opencti.io
Other
6.51k stars 959 forks source link

[Workbench] Problem of management of access #8961

Open Lhorus6 opened 3 weeks ago

Lhorus6 commented 3 weeks ago

Description

Problem: If I am a "read only" user (e.g. only the "Access knowledge" capability), I can still see the workbenches created by other users in the Data tabs of the entities. However, if I click on them to open them, I am thrown out (back to the login page) without any information.

Environment

OCTI 6.3.11

Reproducible Steps

Steps to create the smallest reproducible scenario:

  1. With an admin user, create a report A, import a pdf in the report A's Data tab, and generate a workbench (if it has not been generated automatically).
  2. Create a User B with all marking allowed and only "Access knowledge" capability
  3. Log in with user B
  4. Go on the report A's Data tab.
  5. Click on the workbench

Expected Output

Ideas:

In any case, do not throw me out without information

nino-filigran commented 2 weeks ago

I agree, it's an ugly way to handle the situation. For me, we should allow access but not validate (3rd option).