Bug 1460145

Summary: [ursxF5mB]The message of forbidden without assign permission to create templateinstance could be more friendly
Product: OpenShift Container Platform Reporter: XiuJuan Wang <xiuwang>
Component: Service BrokerAssignee: Jim Minter <jminter>
Status: CLOSED ERRATA QA Contact: XiuJuan Wang <xiuwang>
Severity: low Docs Contact:
Priority: medium    
Version: 3.6.0CC: aos-bugs, smunilla, xtian
Target Milestone: ---   
Target Release: 3.7.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
The error message returned when a user does not have permission to modify a TemplateInstance was improved.
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-11-28 21:56:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description XiuJuan Wang 2017-06-09 09:03:06 UTC
Description of problem:
The message of forbidden without assign permission to create templateinstance is urgly.

Version-Release number of selected component (if applicable):

oc v3.6.100
kubernetes v1.6.1+5115d708d7
features: Basic-Auth GSSAPI Kerberos SPNEGO

Server https://***:443
openshift v3.6.100
kubernetes v1.6.1+5115d708d7

How reproducible:
always

Steps to Reproduce:
1.Enable template service broker by admin
2.Create a templateinstance with requester.username that is not the requester user


Actual results:
step2:
Show below forbidden message:
The TemplateInstance "instance1" is invalid: spec.requester.username: Forbidden: impersonation forbidden: templateinstances.template.openshift.io "" is forbidden: User "xiuwang" cannot "assign" "templateinstances.template.openshift.io" with name "" in project "xiu3"


Expected results:
The forbidden message should be more friendly

Additional info:

Comment 1 Jim Minter 2017-06-09 10:04:15 UTC
https://github.com/openshift/origin/pull/14538

Comment 2 XiuJuan Wang 2017-06-14 02:40:59 UTC
This issue has fixed in [1]
The forbidden info is more friendly.

The TemplateInstance "instance1" is invalid: spec.requester.username: Forbidden: you do not have permission to set username

[1]
Server https://***:8443
openshift v3.6.106
kubernetes v1.6.1+5115d708d7

Will move to verified after bug status change to on_qa

Comment 4 XiuJuan Wang 2017-07-06 03:22:58 UTC
Test with oc version v3.6.135, this issue has been fixed, move this bug to verified.

Comment 8 errata-xmlrpc 2017-11-28 21:56:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2017:3188