Skip to content
This repository has been archived by the owner on Jan 8, 2019. It is now read-only.

role-based "access denied" not shown in web interface #1687

Open
jhaar opened this issue Nov 12, 2015 · 0 comments
Open

role-based "access denied" not shown in web interface #1687

jhaar opened this issue Nov 12, 2015 · 0 comments

Comments

@jhaar
Copy link

jhaar commented Nov 12, 2015

Hi there

I created a role which has Read/Edit access to a Stream. The Stream is specific to a GELF Input channel.

If I assign that Role to a user, and the user goes to edit that Stream, and they choose a different Input channel (in my case syslog), then the graylog-web/application.log correctly reports

Cannot invoke the action, ... returned 403 Forbidden body: {"type":"ApiError","message":"Not authorized"}

but the web interface shows the error

Could not retrieve error.... Internal server error

So it looks (from an end-user perspective) like a bug with graylog, whereas to my eyes this is simply an incorrect error message. It is a "403", so couldn't graylog-web be changed to report that as "Not authorized"?

Thanks

Jason

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant