← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 2073833] [NEW] Accepting community images

 

Public bug reported:

In the original proposal for community image sharing [1], there was a
section to allow "accepting" a community image. The effect this would
have, is to flag this image for the user as if it was an accepted shared
image, making it appear when listing all images, and also making it
available for use with a name instead of an ID.

In the currently implemented spec [2], this is not possible. There is
also mention that using images by their name is a bad idea, as it opens
up the user to a impersonation attack.

I haven't been able to find the discussion around the finalisation of
the spec to know what were the reasons for this "Accepting a Community
Image" to be removed. I would like to suggest that it be revived as part
of the spec. Is there any reason not to consider this at the moment?


[1] https://wiki.openstack.org/wiki/Glance-v2-community-image-sharing#Accepting_a_.27Community.27_Image

[2] https://specs.openstack.org/openstack/glance-
specs/specs/api/v2/sharing-image-api-v2.html#sharing-images-with-all-
users

** Affects: glance
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to Glance.
https://bugs.launchpad.net/bugs/2073833

Title:
  Accepting community images

Status in Glance:
  New

Bug description:
  In the original proposal for community image sharing [1], there was a
  section to allow "accepting" a community image. The effect this would
  have, is to flag this image for the user as if it was an accepted
  shared image, making it appear when listing all images, and also
  making it available for use with a name instead of an ID.

  In the currently implemented spec [2], this is not possible. There is
  also mention that using images by their name is a bad idea, as it
  opens up the user to a impersonation attack.

  I haven't been able to find the discussion around the finalisation of
  the spec to know what were the reasons for this "Accepting a Community
  Image" to be removed. I would like to suggest that it be revived as
  part of the spec. Is there any reason not to consider this at the
  moment?

  
  [1] https://wiki.openstack.org/wiki/Glance-v2-community-image-sharing#Accepting_a_.27Community.27_Image

  [2] https://specs.openstack.org/openstack/glance-
  specs/specs/api/v2/sharing-image-api-v2.html#sharing-images-with-all-
  users

To manage notifications about this bug go to:
https://bugs.launchpad.net/glance/+bug/2073833/+subscriptions