Bug 1779536

Summary: External/public networks are only visible to Administrator and invisible to other users
Product: Red Hat CloudForms Management Engine Reporter: Rahul Chincholkar <rchincho>
Component: ProvidersAssignee: Sam Lucidi <slucidi>
Status: CLOSED NOTABUG QA Contact: Jad Haj Yahya <jhajyahy>
Severity: high Docs Contact: Red Hat CloudForms Documentation <cloudforms-docs>
Priority: high    
Version: 5.10.12CC: dmetzger, jfrey, jhardy, mshriver, obarenbo
Target Milestone: GAKeywords: TestOnly, ZStream
Target Release: 5.12.0Flags: dmetzger: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1798196 1798197 (view as bug list) Environment:
Last Closed: 2020-06-10 13:08:12 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: Bug
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: Openstack Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1798196, 1798197    

Description Rahul Chincholkar 2019-12-04 07:19:38 UTC
Description of problem:
Openstack provided added as cloud provider using admin user credentials in CFME with tenant mapping enabled.
A CFME group is associated with openstack tenant, and a new user (with role EvmRole-super_administrator) created.

When we login to CFME UI with this non-admin user, we are unable to see the external networks.
Due to this, this non-admin user can't create floating IP for an external network or can't add route external gateway for the external networks.

However, CFME Administrator user can do all of this.

Version-Release number of selected component (if applicable):
CFME 5.10.12.3
RHOSP 13

How reproducible:
Always


Actual results:
Non-admin CFME user who is in a CFME group (with a role which has all permissions for network provider) associated with Openstack tenant can not see the external/public network, 
hence that user can not create floating IP for public networks or can not add the router for external networks.

Expected results:
Non-admin CFME user who is in a CFME group (with a role which has all permissions for network provider) associated with Openstack tenant should see the external/public network, 
and the user should be able to create floating IP for public networks or should be able to add the router for external networks.

Comment 12 CFME Bot 2020-01-31 23:30:00 UTC
New commit detected on ManageIQ/manageiq/master:

https://github.com/ManageIQ/manageiq/commit/1eab9ac6bd73ce8d6ad471a44355550a522674c1
commit 1eab9ac6bd73ce8d6ad471a44355550a522674c1
Author:     Sam Lucidi <slucidi>
AuthorDate: Wed Jan 29 15:13:08 2020 -0500
Commit:     Sam Lucidi <slucidi>
CommitDate: Wed Jan 29 15:13:08 2020 -0500

    Make External-facing networks available to all tenants

    External-facing networks, at least in Openstack, are supposed
    to be scoped to all tenants. This updates the tenant_id
    clause for CloudNetworks to consider whether external_facing
    is true when deciding whether to allow a tenant to see a network.

    Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1779536

 app/models/cloud_network.rb | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)