Describe the bug
Pulse's "Security score" banner (shown at the top of pages until dismissed for 1 day/1 week/forever) and the corresponding Settings | Security Overview page report incorrect
"No"/critical status for settings-derived checks (Export requires authentication, Audit logging enabled, HTTPS, API token, Proxy auth) when viewed by a non-admin RBAC role , even when those features are correctly configured. Confirmed by comparing the same instance's reported state when viewed as local admin vs. a non-admin role.
To reproduce
- Enable Pulse Pro / RBAC with a properly configured, secure instance (HTTPS, audit logging, export protection all enabled)
- Log in as a non-admin RBAC role (tested with Viewer, and a custom role granted read:* plus explicit read:settings).
- Observe the "Security score" banner and/or Settings | Security Overview.
- Log in as local admin , the same instance now correctly reports these as enabled.
Expected behavior
Either the banner/page should reflect the instance's actual security posture regardless of viewer role, or it should indicate "insufficient permissions to view security status" rather than a false negative, for any role lacking full admin access.
Pulse version
v6.1.2
Agent version
v6.1.2
Image tag or digest
This field should be optional when LXC is selected
Installation type
ProxmoxVE LXC
Relevant logs or diagnostics
Confirmations
Describe the bug
Pulse's "Security score" banner (shown at the top of pages until dismissed for 1 day/1 week/forever) and the corresponding Settings | Security Overview page report incorrect
"No"/critical status for settings-derived checks (Export requires authentication, Audit logging enabled, HTTPS, API token, Proxy auth) when viewed by a non-admin RBAC role , even when those features are correctly configured. Confirmed by comparing the same instance's reported state when viewed as local admin vs. a non-admin role.
To reproduce
Expected behavior
Either the banner/page should reflect the instance's actual security posture regardless of viewer role, or it should indicate "insufficient permissions to view security status" rather than a false negative, for any role lacking full admin access.
Pulse version
v6.1.2
Agent version
v6.1.2
Image tag or digest
This field should be optional when LXC is selected
Installation type
ProxmoxVE LXC
Relevant logs or diagnostics
Confirmations