Opportunity to do actions(delete,get, and etc) with package from another tenant

Bug #1312190 reported by Sergey Murashov
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Murano
Fix Released
High
Ekaterina Chernova

Bug Description

Steps to reproduce:
1. Install murano from master branch
2. Upload package with paramater "is_public":False for one tenant
3. Try to delete, get, update uploaded package from another tenant

Actual result:
Action is successfully

Changed in murano:
milestone: none → 0.5
importance: Undecided → Medium
summary: - Opportunity to delete package from another tenant
+ Opportunity to do actions(delete,get) package from another tenant
summary: - Opportunity to do actions(delete,get) package from another tenant
+ Opportunity to do actions(delete,get, and etc) package from another
+ tenant
description: updated
Changed in murano:
importance: Medium → High
summary: - Opportunity to do actions(delete,get, and etc) package from another
+ Opportunity to do actions(delete,get, and etc) with package from another
tenant
Changed in murano:
status: New → Confirmed
Revision history for this message
Timur Nurlygayanov (tnurlygayanov) wrote :

Ruslan, need to find who can fix it.

Changed in murano:
assignee: nobody → Ruslan Kamaldinov (ruhe)
Changed in murano:
assignee: Ruslan Kamaldinov (ruhe) → Ekaterina Fedorova (efedorova)
status: Confirmed → In Progress
Revision history for this message
Ekaterina Chernova (efedorova) wrote :

We can forbid actions only for non-admin users for non-public packages.
Blueprint for supporting all cases proposed to Juno milestone https://blueprints.launchpad.net/murano/+spec/admin-rights-restriction

Revision history for this message
Openstack Gerrit (openstack-gerrit) wrote : Fix merged to murano-api (master)

Reviewed: https://review.openstack.org/90900
Committed: https://git.openstack.org/cgit/stackforge/murano-api/commit/?id=5b9ef90b686fec37ba0efc99e6e8cd1ccdbaad48
Submitter: Jenkins
Branch: master

commit 5b9ef90b686fec37ba0efc99e6e8cd1ccdbaad48
Author: Ekaterina Fedorova <email address hidden>
Date: Tue Apr 29 11:19:48 2014 +0400

    Fix issue with user permission on package deletion

    Forbid deletion of non-owned packages for non-admin users
    Closes-Bug: #1312190
    Change-Id: I06d79cc7530b64c9c84dbf09e332dffc48843ab8

Changed in murano:
status: In Progress → Fix Committed
ruhe (ruhe)
Changed in murano:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.