← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1581203] [NEW] Default policy allows unrestricted CRUD on os-server-tags

 

Public bug reported:

The default policy for os-server-tags listed here
(https://github.com/openstack/nova/blob/master/etc/nova/policy.json#L448-L453)
allow all users to do any CRUD operations on all server tags. This
should be limited down to only admin_or_owner.

** Affects: nova
     Importance: Medium
     Assignee: Ryan Rossiter (rlrossit)
         Status: In Progress


** Tags: api policy tags

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/1581203

Title:
  Default policy allows unrestricted CRUD on os-server-tags

Status in OpenStack Compute (nova):
  In Progress

Bug description:
  The default policy for os-server-tags listed here
  (https://github.com/openstack/nova/blob/master/etc/nova/policy.json#L448-L453)
  allow all users to do any CRUD operations on all server tags. This
  should be limited down to only admin_or_owner.

To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1581203/+subscriptions


Follow ups