Created attachment 1113906 [details] diks profile permission screenshot Description of problem: EVERYONE user is assigned two times to a new disk profile Version-Release number of selected component (if applicable): How reproducible: Create a disk profile and check it's permissions by clicking on it (see attached screenshot) Steps to Reproduce: 1. Create an additional disk profile 2. Click on it in Storage->Disk Profiles->'profile name' 3. Look at the permissions Actual results: EVERYONE user is visible two times Expected results: EVERYONE user should only be there once Additional info:
So the default profile currently gets: user admin and role Superuser user EVERYONE with role DiskProfileEditor Every new profile gets user admin and role Superuser user EVERYONE with role DiskProfileEditor user EVERYONE with role DiskProfileUser It might be more correct to have these permissions on the default policy: user admin and role Superuser user <CREATOR> with role DiskProfileEditor user EVERYONE with role DiskProfileUser New profiles should have: user admin and role Superuser user <CREATOR> with role DiskProfileEditor to make it an explicit decision if new profiles should be available for everyone.
Roman note that not every user is a creator. For example if I'm an end user (student), I may not be able to create a (disk, vNIC, VM), but I should still be able to consume one or more profiles based on my permissions (including any LDAP group I belong to).
doesn't seem interesting enough, no complaints anywhere, low severity Please reopen if still interesting