You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm using this plugin to authenticate into Redmine via Keycloack, but once enabled I'm seeing that non-admin users are able to access the /admin page by appending /admin to the hostname. Once on that page, they have read access to a majority of and both read and write access to several, of the admin settings. Pages, where they have read and write access, include, "Users" and all plugins.
I tested this with several different settings changes in both the plugin and within Keycloak and it has not alleviated the issue.
I'm using this plugin to authenticate into Redmine via Keycloack, but once enabled I'm seeing that non-admin users are able to access the
/admin
page by appending/admin
to the hostname. Once on that page, they have read access to a majority of and both read and write access to several, of the admin settings. Pages, where they have read and write access, include, "Users" and all plugins.I tested this with several different settings changes in both the plugin and within Keycloak and it has not alleviated the issue.
Has anyone else had this same issue?
Application: Docker Bitnami/Redmine 4.1.1 and Docker Redmine 4.1.1
Plugin Version: 0.9.4
IDP: Keycloak
The text was updated successfully, but these errors were encountered: