Rethink permission requirements for Admin API DescribeCluster endpoint
Closed this issue · 3 comments
mantas-sidlauskas commented
Context
Cadence WEB is using admin.DescribeCluster
API call to check if advanced visibility options are available for a cluster.
All admin.*
calls require admin
level token when OAuth is enabled. This makes WEB unusable for a user who has only "read" level access to specific domain(s).
There are multiple options how to resolve this issue:
- Change
DescribeCluster
to require read level, you can't change anything anyway - Move this endpoint to "Frontend" API, change WEB to request Frontend API
d-vignesh commented
Hi @demirkayaender , does this require backend or frontend change. If backend, i would like to work on this, can you please provide some context on what are the required changes here.
osho-20 commented
would like to work on this.
mantas-sidlauskas commented