When a user only has privileges on instance:cdap, no matter READ/WRITE/ADMIN, he is able to list all namespaces, and the entities in the namespace.
Steps to reproduce:
1. Have a user without any privilege to any namespace
2. Grant the user action ADMIN on instance:cdap
3. Wait the cache to take effect, he will be able to list namespaces and all entities in the namespace.