← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 2104173] [NEW] network topology UI too enthusiastic about deletions

 

Public bug reported:

The attached screenshots are from the 'network topology' horizon panel.
I'm running as a user with restricted read-only rights, and yet the UI
suggests that I delete VMs (which I am not allowed to delete) and
networks (which I am not allowed to delete.)

This isn't a security issue since the neutron and nova APIs won't
actually allow the deletion. Still, the UI wrong and alarming.

We need policy checks around these buttons.

** Affects: horizon
     Importance: Undecided
         Status: New

** Attachment added: "delete_network.png"
   https://bugs.launchpad.net/bugs/2104173/+attachment/5867239/+files/delete_network.png

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Dashboard (Horizon).
https://bugs.launchpad.net/bugs/2104173

Title:
  network topology UI too enthusiastic about deletions

Status in OpenStack Dashboard (Horizon):
  New

Bug description:
  The attached screenshots are from the 'network topology' horizon
  panel. I'm running as a user with restricted read-only rights, and yet
  the UI suggests that I delete VMs (which I am not allowed to delete)
  and networks (which I am not allowed to delete.)

  This isn't a security issue since the neutron and nova APIs won't
  actually allow the deletion. Still, the UI wrong and alarming.

  We need policy checks around these buttons.

To manage notifications about this bug go to:
https://bugs.launchpad.net/horizon/+bug/2104173/+subscriptions