Cloud Admin user cannot view admin/users/ or admin/projects/ when in alternate domain context

Bug #1850506 reported by Drew Freiberger
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Dashboard Charm
New
Undecided
Unassigned

Bug Description

19.10 charms
bionic-stein

When the cloud admin user logs into horizon (admin_domain/admin juju-created user), the user can view admin_domain users and projects, but if you visit admin/domains/ and enter domain context for something like "default" or "service_domain", etc, the user cannot see any users or projects within the domain via Horizon.

CLI works fine to run 'openstack project list --domain service_domain' or 'openstack user list --domain service_domain'.

I enabled keystone debug logging and all RBAC calls are returning 'Authorization granted', so I believe this is a bug in openstack_dashboard, the new custom policy configurations for 19.10 charms, or perhaps a Stein-related openstack-dashboard bug.

Revision history for this message
Drew Freiberger (afreiberger) wrote :

Special note, the environment where this is being witnessed has upgraded from xenial-queens, through bionic-queens, bionic-rocky, and is now running bionic-stein.

Revision history for this message
Drew Freiberger (afreiberger) wrote :
Revision history for this message
Drew Freiberger (afreiberger) wrote :

I tested the workaround noted in that comment 7 of the RH bug by commenting out the DEFAULT_DOMAIN in /etc/openstack-dashboard/local_settings.py and restarting apache2, but this did not solve the issue. I guess that upstream bug was already closed, this is a separate issue.

Revision history for this message
Alex Kavanagh (ajkavanagh) wrote :

This is a duplicate of https://bugs.launchpad.net/charm-openstack-dashboard/+bug/1830782 which is due to an upstream bug. Unfortunately, there's not much that can be done apart from fixing it upstream.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.