Only admin users should be able to change the user_visible value
Bug #1377230 reported by
Sylvain Afchain
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenContrail |
New
|
Undecided
|
Sylvain Afchain |
Bug Description
Currently a non admin user is able to create a resource with the user_visible attribute changed. So it means that a user could set a resource that it couldn't not see.
Changed in opencontrail: | |
assignee: | nobody → Sylvain Afchain (sylvain-afchain) |
tags: | added: config |
To post a comment you must log in.
Reviewed: https:/ /review. opencontrail. org/3400 github. org/Juniper/ contrail- controller/ commit/ 6e17b4653cda023 11d6e09fa7e2abd 49ff7aee39
Committed: http://
Submitter: Zuul
Branch: master
commit 6e17b4653cda023 11d6e09fa7e2abd 49ff7aee39
Author: Sylvain Afchain <email address hidden>
Date: Fri Oct 3 18:18:12 2014 +0200
Only allows admin users to change the user_visible
This patch add a check to avoid a non admin user
to change the default user_visible value.
Change-Id: Iba48443f97fe0d ac2f63f8350a891 bd06ee50f1f
Closes-bug: #1377230