Skip to content

UI: a role denied one non-essential bootstrap API (e.g. listLdapConfigurations) fails to load the entire console #13912

Description

@kristofer-atlas

problem

The web console fails to load entirely for any role denied one non-essential bootstrap read. GetInfo runs several independent calls under a single shared Promise and wires several to the same reject, including listLdapConfigurations, which only sets a flag. When a role denies it the 432 rejects the shared promise before listApis can resolve it (a race the small query usually wins), so GetInfo rejects and the router guard logs the user out instead of building routes. The tolerant pattern sits right beside it: listNetworkServiceProviders swallows its own error and the console still loads (listGuiThemes likewise).

Expected: a denied non-essential read degrades like listNetworkServiceProviders/listGuiThemes. Actual: blank console, redirect to /user/login.

versions

4.22 and current main. Client-side UI only; hypervisor/storage/network irrelevant.

The steps to reproduce the bug

  1. Create a custom role (e.g. from the DomainAdmin base type) that denies listLdapConfigurations.
  2. Assign an account to it.
  3. Log in to the web UI — the console never renders and you are redirected to login.

What to do about it?

Give listLdapConfigurations (and any non-essential bootstrap read) its own .catch that defaults the flag, as listNetworkServiceProviders already does. The underlying hazard is the shared resolve/reject across independent calls in GetInfo; reserve reject for genuinely essential calls such as listApis.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions