[Openstack-security] [Bug 1445335] Re: create/delete flavor permissions should be controlled by policy.json
Divya K Konoor
dikonoor at in.ibm.com
Tue Apr 21 05:25:41 UTC 2015
Jeremy , this bug does not cause security vulnerability. I am a bit new
to using launchpad (I am not sure if the security tag addition was the
cause ) . This defect merely overrides the flexibility to apply/control
permissions associated with flavor rest api and mandates that only a
user with admin permissions can make these calls.
--
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1445335
Title:
create/delete flavor permissions should be controlled by policy.json
Status in OpenStack Compute (Nova):
Confirmed
Status in OpenStack Security Advisories:
Incomplete
Bug description:
The create/delete flavor rest api always expects the user to be of
admin privileges and ignores the rule defined in the nova/policy.json.
This behavior is observed after these changes >>
https://review.openstack.org/#/c/150352/.
The expected behavior is that the permissions are controlled as per
the rule defined in the policy file and should not mandate that only
an admin should be able to create/delete a flavor
To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1445335/+subscriptions
More information about the Openstack-security
mailing list