Comment 2 for bug 1397069

Revision history for this message
Dmitry Mescheryakov (dmitrymex) wrote :

Ok, after talking a little more with Timur: user will not get access to any objects he have no access according to _components_ policies (keystone, nova, neutron, etc.). User will just see tables he should not see (like admin interface), but the tables will not list any objects user is not allowed. Neither user will be able to perform any operations on objects he is not allowed to. So that is not a security issue, but rather a UX one: user will see parts of the interface which will not work for him. Hence lowering importance back to 'high'.