Adding some context from IRC conversations I had recently on this bug,
the latest proposed fixes do not include the tasks related fix. So, the in flight review atm -- https://review.openstack.org/#/q/I17a66eca55bfb83107046910e69c4da01415deec,n,z , do not include the fix from https://bugs.launchpad.net/glance/+bug/1498163/comments/13 for getting rid if this vulnerability via tasks.
This is definitely out of some confusion so, I think we need to send another patch for tasks to avoid more of the same.
Adding some context from IRC conversations I had recently on this bug,
the latest proposed fixes do not include the tasks related fix. So, the in flight review atm -- https:/ /review. openstack. org/#/q/ I17a66eca55bfb8 3107046910e69c4 da01415deec, n,z , do not include the fix from https:/ /bugs.launchpad .net/glance/ +bug/1498163/ comments/ 13 for getting rid if this vulnerability via tasks.
This is definitely out of some confusion so, I think we need to send another patch for tasks to avoid more of the same.