yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #50788
[Bug 1581203] [NEW] Default policy allows unrestricted CRUD on os-server-tags
Public bug reported:
The default policy for os-server-tags listed here
(https://github.com/openstack/nova/blob/master/etc/nova/policy.json#L448-L453)
allow all users to do any CRUD operations on all server tags. This
should be limited down to only admin_or_owner.
** Affects: nova
Importance: Medium
Assignee: Ryan Rossiter (rlrossit)
Status: In Progress
** Tags: api policy tags
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/1581203
Title:
Default policy allows unrestricted CRUD on os-server-tags
Status in OpenStack Compute (nova):
In Progress
Bug description:
The default policy for os-server-tags listed here
(https://github.com/openstack/nova/blob/master/etc/nova/policy.json#L448-L453)
allow all users to do any CRUD operations on all server tags. This
should be limited down to only admin_or_owner.
To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1581203/+subscriptions
Follow ups