opencti icon indicating copy to clipboard operation
opencti copied to clipboard

Different roles and groups see different data in the dashboard.

Open misohouse opened this issue 1 year ago • 7 comments

OpenCTI Version : 6.1.10

In the photo below, the left side is the dashboard screen for a user with the Administrator, Default Role and Group, on the right is the dashboard for a user with the External role and Group. 11 . . . The data that exists in the platform is the same, so I don't understand why the two dashboards show different data.

Is this a bug?

Your answer would be greatly appreciated.

misohouse avatar Jun 27 '24 02:06 misohouse

@misohouse to help you out, can you provide us with:

  • capabilities associated with each role
  • marking associated with each group
  • organisation associated with each user (to which organisation they belong)
  • if you have set a platform organisation (visible in setting/security/policies)

nino-filigran avatar Jun 27 '24 07:06 nino-filigran

@nino-filigran

Here is information about role and group. . . . [1] Administrator Role 11 . . [2] Default Role 22 . . [3] External Role 33 . . [4] External account information 44 . . [5] Administrator account information 55 . . If you need more information, I'll add it.

misohouse avatar Jun 27 '24 08:06 misohouse

Can you provide the allowed marking fro your groups?

nino-filigran avatar Jun 27 '24 10:06 nino-filigran

@nino-filigran Sure, here it is. . . . [6] Administrator Groups ad . . [7] Default Groups de . . [8] External Groups ex

misohouse avatar Jun 27 '24 13:06 misohouse

To recap my understanding, users of external group (first screenshot on the right in your ticket) see less info than users from default/admin (first screenshot on the left).

Based on your responses and screenshots, the reason is simple: your external group have less marking than your default admin (in the "allowed markings"). They cannot see anything above TLP:AMBER, which is the reason you have some discrepencies.

nino-filigran avatar Jun 28 '24 07:06 nino-filigran

@nino-filigran

If you're right, shouldn't we rather see less information in the External account?

If you look at the screenshot I posted at the very beginning, it actually shows less information in the Administrator account (the dashboard shows no data).

Note that most data is currently written as TLP:GREEN and TLP:CLEAR.

Am I misunderstanding something?

misohouse avatar Jun 28 '24 07:06 misohouse

You're completly right, sorry about this, I've mixed up your dashboards and focused on the numbers widgets. I'll keep investigating!

nino-filigran avatar Jun 28 '24 07:06 nino-filigran

@misohouse sorry for not following up this earlier. Do you still encounter the issue?

nino-filigran avatar Jul 31 '24 07:07 nino-filigran

@nino-filigran

Hi, I'm still experiencing the same issue and waiting for a solution.

(Administrator) 11

(External) 22

misohouse avatar Aug 01 '24 05:08 misohouse

@misohouse we're still trying to understand what could be the issue, however, we struggle with this since we're not able to reproduce at all your situation. I guess since then you've upgraded to most recent version, right? And tried to clear your local storage?

nino-filigran avatar Aug 01 '24 08:08 nino-filigran

Hi @misohouse when you have empty widget with your administrator do you have any log ? Could you provide a support package after accessing the dashboard with your admin ?

Kedae avatar Aug 01 '24 11:08 Kedae

@misohouse we're still trying to understand what could be the issue, however, we struggle with this since we're not able to reproduce at all your situation. I guess since then you've upgraded to most recent version, right? And tried to clear your local storage?

Yes I am currently using the latest version, and the local storage is not being cleared because it has existing data.

misohouse avatar Aug 02 '24 02:08 misohouse

We're still having issue on our side to reproduce the issue, making the investigation stuggling for information. Could you please provide a support package as requested above when you have an emtpy widget?

nino-filigran avatar Aug 19 '24 07:08 nino-filigran

@nino-filigran

Ah I solved the problem!

I changed the date type to “Technical date” in the settings on the bottom right of the platform and it looks fine :) 11 22

misohouse avatar Aug 20 '24 08:08 misohouse

I'm glad to hear it @misohouse thanks for informing us! I'm closing the bug as a result. Feel free to re-open it if you still have an issue/comment.

nino-filigran avatar Aug 20 '24 14:08 nino-filigran