yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #94291
[Bug 2073833] [NEW] Accepting community images
Public bug reported:
In the original proposal for community image sharing [1], there was a
section to allow "accepting" a community image. The effect this would
have, is to flag this image for the user as if it was an accepted shared
image, making it appear when listing all images, and also making it
available for use with a name instead of an ID.
In the currently implemented spec [2], this is not possible. There is
also mention that using images by their name is a bad idea, as it opens
up the user to a impersonation attack.
I haven't been able to find the discussion around the finalisation of
the spec to know what were the reasons for this "Accepting a Community
Image" to be removed. I would like to suggest that it be revived as part
of the spec. Is there any reason not to consider this at the moment?
[1] https://wiki.openstack.org/wiki/Glance-v2-community-image-sharing#Accepting_a_.27Community.27_Image
[2] https://specs.openstack.org/openstack/glance-
specs/specs/api/v2/sharing-image-api-v2.html#sharing-images-with-all-
users
** Affects: glance
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to Glance.
https://bugs.launchpad.net/bugs/2073833
Title:
Accepting community images
Status in Glance:
New
Bug description:
In the original proposal for community image sharing [1], there was a
section to allow "accepting" a community image. The effect this would
have, is to flag this image for the user as if it was an accepted
shared image, making it appear when listing all images, and also
making it available for use with a name instead of an ID.
In the currently implemented spec [2], this is not possible. There is
also mention that using images by their name is a bad idea, as it
opens up the user to a impersonation attack.
I haven't been able to find the discussion around the finalisation of
the spec to know what were the reasons for this "Accepting a Community
Image" to be removed. I would like to suggest that it be revived as
part of the spec. Is there any reason not to consider this at the
moment?
[1] https://wiki.openstack.org/wiki/Glance-v2-community-image-sharing#Accepting_a_.27Community.27_Image
[2] https://specs.openstack.org/openstack/glance-
specs/specs/api/v2/sharing-image-api-v2.html#sharing-images-with-all-
users
To manage notifications about this bug go to:
https://bugs.launchpad.net/glance/+bug/2073833/+subscriptions