Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Read only user group

    webGUI
    2
    3
    2.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      HCJ
      last edited by

      Hi, can this be done now? and if so how do I do it? I want a read only group, so people can log in, view the stats/rules etc, but not be able to make any changes.

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        I made a ViewAll group the other day, like in the attached screenshot.
        "User - Config - Deny Config Write" stops any changes to the config actually happening. When I login as "view.phil" and make changes then press Save, there is no message telling me it won't save, but actually it doesn't save, and then there is no "Apply" button coming, because it did not actually make any config changes.

        But the user can mess with the running system things like:
        a) Status->Services - stop and start services
        b) Diagnostics->Command Prompt - execute general PHP and shell commands, thus possibly wreaking havoc. (Might be other stuff in Diagnostics that also does real things to the disk…)
        c) Do package installs (and I guess removals!) - I just does not write anything into the config after the install. For example I just installed bandwidthd from view.phil - /usr/local/pkg has bandwidthd files in it... But System->Packages screen does not show it, because the end step to list it in the config did not happen.
        and...

        It would be nice to have some versions of read-only that prohibit:

        1. Config changes (already available like here)
        2. Config changes and disk changes
        3. Config changes, disk changes and in memory changes (all changes prohibited)

        Anyone who knows how to achieve this in 2.1.5 or 2.2 please advise...

        ViewAll-pfSense-Group.png
        ViewAll-pfSense-Group.png_thumb

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • H
          HCJ
          last edited by

          many thanks for repling, I'll take a look.

          Ideally I would like read only access, apart from allowing changes to one firewall host alliases, to add in people who need the penalty box - I guess this level of lock down isn't available yet ?

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.