Octavia needs to validate the requester has permission to create/update objects

Bug #1662985 reported by Michael Johnson
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
octavia
Fix Released
High
Michael Johnson

Bug Description

Once keystone is available we need to make sure we are validating that the user has permission for the resources they are accessing.

1. Make sure that requests specifying a project id (lb create) either matches the requester project ID or is an admin role users.
2. Make sure any requests for objects (load_balancer, listener, etc.) have a keystone project_id that matches the object's project_id or has an admin role.

This can be implemented as a hook.

Tags: lbaas-merge
Changed in octavia:
status: Triaged → In Progress
assignee: nobody → Michael Johnson (johnsom)
Revision history for this message
Michael Johnson (johnsom) wrote :
Changed in octavia:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.