[openstack-dev] [nova] Non-Admin user can show deleted instances using changes-since parameter when calling list API

Zhenyu Zheng zhengzhenyulixi at gmail.com
Wed Mar 2 09:02:09 UTC 2016


Hi, Nova,

While I'm working on add "changes-since" parameter support for
python-novaclient "list" CLI.

I realized that non-admin can list all deleted instances using
"changes-since" parameter. This is reasonable in some level, as delete is
an update to instances. But as we have a limitation that when list
instances, deleted parameter is only allowed for admin users.

This will lead to inconsistent to the rule of show deleted instances, as we
limit the list of deleted instances to admin only, but non-admin can get
the information using changes-since.

Should we fix this?

https://bugs.launchpad.net/nova/+bug/1552071

Thanks,

Kevin Zheng
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20160302/147d82c1/attachment.html>


More information about the OpenStack-dev mailing list