| Summary: | [REST API]: GET'ing domain with bad credentials returns 404 | ||
|---|---|---|---|
| Product: | OKD | Reporter: | Andre Dietisheim <adietish> |
| Component: | Pod | Assignee: | Krishna Raman <kraman> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | libra bugs <libra-bugs> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 2.x | CC: | lnader, mfisher, mpatel, xcoulon, xtian |
| Target Milestone: | --- | Keywords: | Triaged |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-04-13 18:32:24 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Andre Dietisheim
2012-03-23 11:45:06 UTC
The very same request (to the same existing domain) while using valid credentials, lists the expected informations. since this is on production the authentication should be failing and routing the user to login or return a 401. switched severity to urgent since we cannot differentiate if a user has no domain or he's simply not authorized 5764b5c849d19492c7186cf5d3bd66dfd564e955 (In reply to comment #4) > 5764b5c849d19492c7186cf5d3bd66dfd564e955 Test this on devenv_1679, configure the instance to integrated environment (which will require authentication for user), Access with invalid password will return access denied curl -k -H 'Accept: application/xml' --user 'xtian+test5:invalidpwd' https://$instancedns/broker/rest/domains/doms6 -X GET HTTP Basic: Access denied. Access with valid password but non-exist domain: curl -k -H 'Accept: application/xml' --user 'xtian+test5:validpwd' https://$instancedns/broker/rest/domains/doms7 -X GET <?xml version="1.0" encoding="UTF-8"?> <response> <type nil="true"></type> <data> <datum nil="true"></datum> </data> <messages> <message> <exit-code>127</exit-code> <severity>error</severity> <text>Domain doms7 not found.</text> <field nil="true"></field> </message> </messages> <status>not_found</status> <version>1.0</version> </response> *** Bug 806293 has been marked as a duplicate of this bug. *** looks perfect, thanks! |