Bug 1313065

Summary: fetching lazy files over http results in Forbidden
Product: Red Hat Satellite Reporter: Justin Sherrill <jsherril>
Component: WebUIAssignee: Justin Sherrill <jsherril>
Status: CLOSED ERRATA QA Contact: Roman Plevka <rplevka>
Severity: high Docs Contact:
Priority: unspecified    
Version: 6.2.0CC: bbuckingham, ehelms, rplevka, sthirugn
Target Milestone: UnspecifiedKeywords: Triaged
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
URL: http://projects.theforeman.org/issues/13961
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-07-27 09:03:08 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Justin Sherrill 2016-02-29 20:45:11 UTC
Description of problem:

When trying to fetch files from a kickstart tree such as:

/pulp/repos/Default_Organization/Library/custom/kickstart/http-cdn-test/images/pxeboot/vmlinuz

fails with a Forbidden error when the repo is using lazy syncing

Version-Release number of selected component (if applicable):
6.2.0 SNAP 1

How reproducible:
Always

Steps to Reproduce:
1.  Sync the 6.6 kickstart tree 
2.  In the browser try to fetch http://hostname/pulp/repos/Default_Organization/Library/content/dist/rhel/server/6/6.6/x86_64/kickstart/images/pxeboot/vmlinuz
(adjusting the hostname and org name as appropriate)

Actual results:
Forbidden

Expected results:
The file downloads (after a redirect)


Additional info:

Comment 1 Justin Sherrill 2016-02-29 20:47:22 UTC
Created redmine issue http://projects.theforeman.org/issues/13961 from this bug

Comment 3 Bryan Kearney 2016-02-29 21:11:20 UTC
Upstream bug component is WebUI

Comment 4 Bryan Kearney 2016-03-14 14:11:32 UTC
Moving to POST since upstream bug http://projects.theforeman.org/issues/13961 has been closed

Comment 6 Roman Plevka 2016-04-01 16:03:06 UTC
VERIFIED
on sat 6.2.0 Snap #6.

accessing
http://<sat6server>/pulp/repos/Default_Organization/Library/content/dist/rhel/server/6/6.6/x86_64/kickstart/images/pxeboot/vmlinuz

after enabling&syncing the kickstart repo with download_policy: ondemand

now triggers 302 with Location header set to: 
"http://<sat6server>:80/streamer/var/lib/pulp/content/units/distribution/ac/a<hash>%3D;signature=<signature_hash>"

which finally results in 200 providing the vmlinuz file

Comment 8 errata-xmlrpc 2016-07-27 09:03:08 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2016:1500