Climate V2 API lets a non admin user list all leases

Bug #1306231 reported by Pablo Andres Fuente
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Blazar
Won't Fix
Medium
Pablo Andres Fuente

Bug Description

The V2 API lets a non admin user list all leases. This can be reproduced creating a lease using admin user, another lease using a non admin user, and then if you try to get all the leases using the non admin user, you will can get the admin lease too.

This could not be reproduced using the climate client, because it supports V1 API only.

Revision history for this message
Dina Belova (dbelova) wrote :

Connected with https://bugs.launchpad.net/climate/+bug/1304435

Fix should fix both of them.

Changed in climate:
importance: Undecided → Medium
status: New → Confirmed
Changed in climate:
assignee: nobody → Pablo Andres Fuente (pablo-a-fuente)
Changed in blazar:
status: Confirmed → In Progress
Revision history for this message
fatemehj (f-jabbari) wrote :

It seems that this bug has resolved in https://review.openstack.org/#/c/97286/

Revision history for this message
Masahito Muroi (muroi-masahito) wrote :

Current v2 API is development implementation and has no plan to be supported version.

Changed in blazar:
status: In Progress → Won't Fix
Revision history for this message
Pierre Riteau (priteau) wrote :

Actually this is also happening with API v1.

Revision history for this message
Pierre Riteau (priteau) wrote :

I take it back: I was using the same project for both admin and non-admin in DevStack.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on blazar (master)

Change abandoned by Pierre Riteau (<email address hidden>) on branch: master
Review: https://review.openstack.org/97286
Reason: We have deprecated the v2 API, so we won't merge this patch.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.