| Summary: | Non user can stop an instance created by admin even when all deployable permissions are revoked. | ||
|---|---|---|---|
| Product: | [Retired] CloudForms Cloud Engine | Reporter: | Shveta <ssachdev> |
| Component: | aeolus-conductor | Assignee: | Scott Seago <sseago> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | wes hayutin <whayutin> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 1.0.0 | CC: | akarol, deltacloud-maint, ssachdev |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Shveta
2011-12-15 09:41:28 UTC
adding to ce-sprint-next adding to ce-sprint-next adding to ce-sprint removing ce-sprint-next tracker Stopping an instance won't depend on deployable permissions. However, if the non-admin user in question wasn't the one that launched the instance, this is still a bug -- conductor should be verifying that the user has 'Use Instance' permissions on the instance being stopped. What page did you access to stop the instance? I attempted to test this out and, as non-admin user without depoyment rights, when I clicked on the deployment URL I got an 'insufficient privileges' error page, so I could not get to the instance list. If you could provide the URL of the page on which you were able to stop the instance on which you shouldn't have had access, that would help me track this down. This is changed/fixed recently it seems. Error not reproducible . Verified in rpm -qa|grep aeolus aeolus-conductor-0.8.0-7.el6.noarch aeolus-configure-2.5.0-4.el6.noarch aeolus-conductor-daemons-0.8.0-7.el6.noarch rubygem-aeolus-image-0.3.0-2.el6.noarch rubygem-aeolus-cli-0.3.0-3.el6.noarch aeolus-all-0.8.0-7.el6.noarch aeolus-conductor-doc-0.8.0-7.el6.noarch |