intuitem / ciso-assistant-community

CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management and supporting +70 frameworks worldwide with auto-mapping: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC, PSPF, GDPR, HIPAA, Essential Eight, NYDFS-500, DORA, NIST AI RMF, 800-53, 800-171, CyFun, CJIS, AirCyber, NCSC, ECC, SCF and so much more
https://intuitem.com
Other
1.16k stars 157 forks source link

Failed loading ESRS library as a Domain Manager #853

Closed casadobarragan closed 1 month ago

casadobarragan commented 1 month ago

Describe the bug When trying to load a library as Domain Manager of a specific domain, it gives Error500.

To Reproduce Steps to reproduce the behavior:

  1. Loggin as a Domine Manager User
  2. Go to 'Extra - Libraries'
  3. Select any library.
  4. Click on the "Load Library" button.
  5. See error500 Captura de pantalla 2024-09-20 a la(s) 3 31 17 p  m

Expected behavior The library should load without any issues and be reflected in the respective section of the Domain, e.g. risk matrices, threats, etc. Screenshots

Environment (please complete the following information):

ab-smith commented 1 month ago

thank you @casadobarragan The problem can indeed be reproduced and is specific to this library. We'll take a look and get back to you

ab-smith commented 1 month ago

in the meantime @casadobarragan try to import another ESRS library and load this one to see if it unlocks the situation

casadobarragan commented 1 month ago

thank you @ab-smith for the support. I tried to load other libraries and it is not possible. I get the same error with any library I try to load such as Domine Manager 😮

eric-intuitem commented 1 month ago

Indeed loading libraries requires administrator right, as libraries are loaded in the global domain. We should make that clear in the UI and not reach the error 500, so this is indeed a bug.