[OSSA 2013-011] Deleted user can still create instances
Bug #1166670 reported by
Sam Stoelinga
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
Fix Released
|
High
|
Dolph Mathews | ||
Folsom |
Fix Released
|
High
|
Dolph Mathews | ||
Grizzly |
Fix Released
|
High
|
Dolph Mathews | ||
OpenStack Security Advisory |
Fix Released
|
Undecided
|
Thierry Carrez | ||
keystone (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Quantal |
Fix Released
|
Undecided
|
Unassigned | ||
Raring |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Description:
A deleted user is still able to create instances and do other stuff if he's still logged in.
Steps to reproduce:
1. Login with admin user in Chrome
2. Login with demo user in Firefox
3. Use the admin user to delete the demo user
4. Go back to firefox and use the demo user to create an instance for example
Current result:
Demo user in firefox stays logged in and can create instances, but I guess he can do anything he want with his token
Expected result:
Demo user shouldn't be able to still create instances, or do other stuff. Instead he should be automatically logged out as soon as we notice that he's already deleted.
description: | updated |
Changed in keystone: | |
status: | New → Incomplete |
description: | updated |
Changed in keystone: | |
assignee: | nobody → Dolph Mathews (dolph) |
information type: | Private Security → Public Security |
summary: |
- Deleted user can still create instances + [OSSA 2013-011] Deleted user can still create instances |
Changed in ossa: | |
assignee: | nobody → Thierry Carrez (ttx) |
status: | New → Fix Released |
Changed in keystone: | |
milestone: | none → havana-1 |
status: | Fix Committed → Fix Released |
tags: |
added: verification-done removed: verification-needed |
Changed in keystone: | |
milestone: | havana-1 → 2013.2 |
To post a comment you must log in.
Not really a Horizon issue, switching to Keystone.
I think this is by design how tokens work, but I will ask for keystone core confirmation first.