Skip to content

[Bug]: Security score banner and Security Overview page show false negatives to non-admin RBAC roles #1675

Description

@123dev

Describe the bug

Pulse's "Security score" banner (shown at the top of pages until dismissed for 1 day/1 week/forever) and the corresponding Settings | Security Overview page report incorrect
"No"/critical status for settings-derived checks (Export requires authentication, Audit logging enabled, HTTPS, API token, Proxy auth) when viewed by a non-admin RBAC role , even when those features are correctly configured. Confirmed by comparing the same instance's reported state when viewed as local admin vs. a non-admin role.

Image Image

To reproduce

  1. Enable Pulse Pro / RBAC with a properly configured, secure instance (HTTPS, audit logging, export protection all enabled)
  2. Log in as a non-admin RBAC role (tested with Viewer, and a custom role granted read:* plus explicit read:settings).
  3. Observe the "Security score" banner and/or Settings | Security Overview.
  4. Log in as local admin , the same instance now correctly reports these as enabled.

Expected behavior

Either the banner/page should reflect the instance's actual security posture regardless of viewer role, or it should indicate "insufficient permissions to view security status" rather than a false negative, for any role lacking full admin access.

Pulse version

v6.1.2

Agent version

v6.1.2

Image tag or digest

This field should be optional when LXC is selected

Installation type

ProxmoxVE LXC

Relevant logs or diagnostics

See the screenshots

Confirmations

  • I verified the exact Pulse version and image reference from the running instance.
  • I searched existing issues for duplicates.

Metadata

Metadata

Assignees

No one assigned

    Labels

    affects-6.1.2Bug reported against Pulse 6.1.2bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions