← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1603579] Re: WebSSO user can't see the "Federation" management panel in Horizon

 

Hi Blake,

Just checking to see if you were able to reproduce this with master?
Marking this as invalid because it sounds specific to how panels are
presented to users, which keystone doesn't determine. It also sounds
like this might not be reproducible with later releases.

Echoing Gary's comment here, but please feel free to reopen if you have
additional information that may change the status of this report.

** Changed in: keystone
       Status: New => Invalid

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Identity (keystone).
https://bugs.launchpad.net/bugs/1603579

Title:
  WebSSO user can't see the "Federation" management panel in Horizon

Status in OpenStack Dashboard (Horizon):
  Invalid
Status in OpenStack Identity (keystone):
  Invalid

Bug description:
  Horizon has the option to set OPENSTACK_KEYSTONE_FEDERATION_MANAGEMENT
  in local_settings.py in order to enable the "Federation" management
  panel - that is CRUD operations on Identity Providers and Federation
  Mappings.

  That works fine for a user logging in using Keystone credentials if the user has admin role.
  However, if I try to login through WebSSO, using an external Identity Provider (ADFS for example), the federated user can't see the "Federation" panel even if he has admin role on the projects.

  I imagine this is a bug and I don't see any reason why the federated
  user with admin role doesn't have access to the Federation panel.

To manage notifications about this bug go to:
https://bugs.launchpad.net/horizon/+bug/1603579/+subscriptions


References