← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1060930] Re: Admin can update metadata of a deleted image

 

** Changed in: glance/grizzly
   Importance: Undecided => Medium

** Changed in: glance/grizzly
       Status: New => Fix Released

** Changed in: glance/grizzly
    Milestone: None => 2013.1

** Changed in: glance/grizzly
     Assignee: (unassigned) => Unmesh Gurjar (unmesh-gurjar)

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to Glance.
https://bugs.launchpad.net/bugs/1060930

Title:
  Admin can update metadata of a deleted image

Status in OpenStack Image Registry and Delivery Service (Glance):
  Fix Released
Status in Glance folsom series:
  Fix Released
Status in Glance grizzly series:
  Fix Released
Status in “glance” package in Ubuntu:
  Fix Released
Status in “glance” source package in Quantal:
  Fix Released

Bug description:
  An admin user has the right to see deleted images. However he does not need to update image metadata
  of a deleted image. Currently this is possible, and I think it should be disabled.

  Steps to Reproduce:
  1. Delete an Image 
  2. Update the image's metadata as an admin.

  Expected result: 
  403 Forbidden or an appropriate response. 
  404 NotFound could be returned but an admin can see deleted images so it may be inappropriate.

  Actual result:
  200 OK, and the image's metadata can get updated.

To manage notifications about this bug go to:
https://bugs.launchpad.net/glance/+bug/1060930/+subscriptions