Admin panel should be displayed only Cloud admin

Bug #1598047 reported by Kenji Ishii
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
OpenStack Dashboard (Horizon)
Confirmed
Medium
Unassigned

Bug Description

In Mitaka, horizon supported domain scoped token[1].
When we use it, we can operate within specified domain scope.
However, if a user have admin role, Admin panel will display.
Information in Admin panel is not only current domain but also all domain.
Therefore, a user who are not operator(cloud admin) is also able to see other domain's info.
In addition, many operation which is allowed by 'admin' can be done by its user.
Originally, other components also should be addressed about keystone v3 model. But now it is not.

[1] https://review.openstack.org/#/c/148082/

Tags: keysone
Kenji Ishii (ken-ishii)
Changed in horizon:
assignee: nobody → Kenji Ishii (ken-ishii)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to horizon (master)

Fix proposed to branch: master
Review: https://review.openstack.org/336431

Changed in horizon:
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on horizon (master)

Change abandoned by Kenji Ishii (<email address hidden>) on branch: master
Review: https://review.openstack.org/336431
Reason: This patch should not be merged as a master.

tags: added: keysone
Akihiro Motoki (amotoki)
Changed in horizon:
assignee: Kenji Ishii (ken-ishii) → nobody
status: In Progress → New
Ivan Kolodyazhny (e0ne)
Changed in horizon:
status: New → Confirmed
importance: Undecided → Medium
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.