From 212b01be971d684f0ce8ad318e7a9fc25345a063 Mon Sep 17 00:00:00 2001 From: "Jose I. Paris" Date: Fri, 4 Jul 2025 17:39:01 +0200 Subject: [PATCH] Enable RBAC for OrgViewers Signed-off-by: Jose I. Paris --- app/controlplane/internal/service/service.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controlplane/internal/service/service.go b/app/controlplane/internal/service/service.go index 8d147ca37..b56cba4cc 100644 --- a/app/controlplane/internal/service/service.go +++ b/app/controlplane/internal/service/service.go @@ -374,7 +374,7 @@ func rbacEnabled(ctx context.Context) bool { // we have an user currentSubject := usercontext.CurrentAuthzSubject(ctx) - return currentSubject == string(authz.RoleOrgMember) + return currentSubject == string(authz.RoleOrgMember) || currentSubject == string(authz.RoleViewer) } // NOTE: some of these http errors get automatically translated to gRPC status codes