Security

How do I grant access to the Edit Account screen for a new role?

mark_fendly
New Member

I've created a new role in the web interface and want users assigned to that role to be able to change their own passwords. I gave the role the change_own_password capability, but when the user signs in and clicks their name, and then Edit Account, they get an error. I don't see any other capabilities that sound like they grant access to that screen. Is there some setting that I'm missing?

0 Karma
1 Solution

rsennett_splunk
Splunk Employee
Splunk Employee

I'm not sure what it would be that would combine with change_own_password, but you may want to allow that role to inherit the capabilities of the lowliest user, the user role.

If there is something in the user role that offends... create a new role say my_user, with all the capability of the user role and inherit it from your new role. Then go back and remove things one by one from your my_user if they offend... checking to be sure that your new role still can edit their own account info.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!

View solution in original post

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

I'm not sure what it would be that would combine with change_own_password, but you may want to allow that role to inherit the capabilities of the lowliest user, the user role.

If there is something in the user role that offends... create a new role say my_user, with all the capability of the user role and inherit it from your new role. Then go back and remove things one by one from your my_user if they offend... checking to be sure that your new role still can edit their own account info.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma

mark_fendly
New Member

I added all of the capabilities from the user role and then removed them one by one. It looks like in addition to change_own_password I also needed both list_inputs and rest_properties_get before it would allow me to access the Edit Account screen.

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Ah... yes. rest_properties_get is most likely how Splunk brings back/accesses the account info... glad you got it to work.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...