Summary: | If a permission depends on group membership, polkit should explicitly check if calling user is a member of that group as well as trying to find all members of the group | ||
---|---|---|---|
Product: | PolicyKit | Reporter: | Adam Williamson <adamw> |
Component: | daemon | Assignee: | David Zeuthen (not reading bugmail) <zeuthen> |
Status: | RESOLVED MOVED | QA Contact: | David Zeuthen (not reading bugmail) <zeuthen> |
Severity: | normal | ||
Priority: | medium | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
Whiteboard: | |||
i915 platform: | i915 features: |
Description
Adam Williamson
2014-08-27 21:01:11 UTC
To be precise, this is not truly about “permissions” but about the users allowed to respond to auth_admin* challenges. I was figuring the 'get_group_members' (or whatever it's called) function was kinda generic and probably used in other cases too... This will be fixed as a part of glibc-2.24 https://sourceware.org/git/?p=glibc.git;a=commit;h=ced8f8933673f4efda1d666d26a1a949602035ed -- GitLab Migration Automatic Message -- This bug has been migrated to freedesktop.org's GitLab instance and has been closed from further activity. You can subscribe and participate further through the new bug through this link to our GitLab instance: https://gitlab.freedesktop.org/polkit/polkit/issues/24. |
Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.