Skip to content

[Security Solution]Create Rule Button showing on Rule Group page with Read Security Privilege  #163462

@ghost

Description

Describe the bug:
Create Rule Button showing on Rule Group page with Read Security Privilege

Kibana/Elasticsearch Stack version
Version: 8.10.0 SNAPSHOT
Commit: f9f2d37
Build: 65764

Browser and Browser OS Version:
Firefox for windows OS
Version: 116.0.2 (64-bit)

Elastic Endpoint Version:
v8.10.0-dev.0

Original install method:
Build summary: https://artifacts-api.elastic.co/v1/search/8.10.0-SNAPSHOT

Functional Area:
Security App side Navigation

Initial Setup:

  • Custom user with Customized privilege ( Set Security Feature to None ) in order to set read access to rule feature of security ( refer below attached screen-shot)

Steps to reproduce

  • Navigate to Rule Details Page page <kibanaurl>/app/security/rules/management
  • Validate the Read glassed icon on page header and crate new rule button to be disabled as user don't have access to create rule
  • Now move to Rule Group listing page <kibanaurl>/app/security/rules/landing
  • Observed that Create Rule button is enabled which is incorrect as user dont have access to create rule

Additional Observation

  • Moreover on clicking on Create Rule button on rule group page it is redirecting us to Rule Details page

Current behavior

  • Create rule button is enabled on Rule Grouping page with Read Access to Security App.

Expected behavior:

  • Create Rule button need to disabled on Rule Grouping page with Read Access to Security App.
  • Read Glasses needed to show in header

Screen-Cast:

SIEM.Rules.-.Kibana.Mozilla.Firefox.Private.Browsing.2023-08-09.12-53-15.mp4

Errors in browser console:
N/A

Any additional context (logs, chat logs, magical formulas, etc.):

N/A

Metadata

Metadata

Assignees

Labels

QA:ValidatedIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeambugFixes for quality problems that affect the customer experiencefixedimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.v8.10.0

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions