yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #47579
[Bug 1551836] Re: CORS middleware's latent configuration options need to change
Reviewed: https://review.openstack.org/287274
Committed: https://git.openstack.org/cgit/openstack/glance/commit/?id=7a93458baa99f6b8c1538f14f521703082af9c42
Submitter: Jenkins
Branch: master
commit 7a93458baa99f6b8c1538f14f521703082af9c42
Author: Michael Krotscheck <krotscheck@xxxxxxxxx>
Date: Wed Mar 2 07:48:05 2016 -0800
Moved CORS middleware configuration into oslo-config-generator
The default values needed for glance's implementation of cors
middleware have been moved from paste.ini into the configuration
hooks provided by oslo.config. Furthermore, these values have been
added to glance's default configuration parsing. This ensures
that if a value remains unset in glance-api.conf, it will be set to use
sane defaults, and that an operator modifying the configuration
file will be presented with a default set of necessary sane headers.
Change-Id: I3c9d267b6224d6c7e5cc2c41cb51fb7e363c4955
Closes-Bug: 1551836
** Changed in: glance
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/1551836
Title:
CORS middleware's latent configuration options need to change
Status in Aodh:
Fix Released
Status in Barbican:
In Progress
Status in Ceilometer:
Fix Released
Status in Cinder:
In Progress
Status in cloudkitty:
In Progress
Status in congress:
In Progress
Status in Cue:
In Progress
Status in Designate:
In Progress
Status in Glance:
Fix Released
Status in heat:
In Progress
Status in Ironic:
Fix Released
Status in OpenStack Identity (keystone):
Fix Released
Status in Magnum:
In Progress
Status in Manila:
In Progress
Status in Mistral:
In Progress
Status in Murano:
Fix Released
Status in neutron:
In Progress
Status in OpenStack Compute (nova):
Fix Released
Status in oslo.config:
Fix Released
Status in Sahara:
Fix Released
Status in OpenStack Search (Searchlight):
In Progress
Status in Solum:
Fix Released
Status in Trove:
In Progress
Bug description:
It was pointed out in http://lists.openstack.org/pipermail/openstack-
dev/2016-February/086746.html that configuration options included in
paste.ini are less than optimal, because they impose an upgrade burden
on both operators and engineers. The following discussion expanded to
all projects (not just those using paste), and the following
conclusion was reached:
A) All generated configuration files should contain any headers which the API needs to operate. This is currently supported in oslo.config's generate-config script, as of 3.7.0
B) These same configuration headers should be set as defaults for the given API, using cfg.set_defaults. This permits an operator to simply activate a domain, and not have to worry about tweaking additional settings.
C) All hardcoded headers should be detached from the CORS middleware.
D) Configuration and activation of CORS should be consistent across all projects.
It was also agreed that this is a blocking bug for mitaka. A reference
patch has already been approved for keystone, available here:
https://review.openstack.org/#/c/285308/
To manage notifications about this bug go to:
https://bugs.launchpad.net/aodh/+bug/1551836/+subscriptions
References