Bug 1400031 - Can override a repo for restricted attributes like baseurl
Summary: Can override a repo for restricted attributes like baseurl
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: subscription-manager
Version: 6.9
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: candlepin-bugs
QA Contact: John Sefler
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-11-30 10:22 UTC by Shwetha Kallesh
Modified: 2018-02-13 08:25 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-12-05 15:51:12 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Shwetha Kallesh 2016-11-30 10:22:00 UTC
Description of problem:
user is allowed to add a override for baseurl attribute which is supposed to be restricted

Version-Release number of selected component (if applicable):
[root@dhcp35-179 ~]# subscription-manager version
server type: Red Hat Subscription Management
subscription management server: 2.0.21-1
subscription management rules: 5.20
subscription-manager: 1.18.5-1.el6
python-rhsm: 1.18.5-1.el6


How reproducible:


Steps to Reproduce:
[root@dhcp35-179 ~]# subscription-manager repo-override --add=name:baseurl 
Error: You must specify a repository to modify

[root@dhcp35-179 ~]# curl -X PUT -H "Content-Type:application/json" -k -u admin:admin "https://shwetha-workstation.usersys.redhat.com:8443/candlepin/activation_keys/8a6a39f58aabbc50158b4969d881417/content_overrides" -d '[{"contentLabel":"awesome-os","name":"baseurl","value":"http://test"}]' 

[ {
  "contentLabel" : "awesome-os",
  "name" : "baseurl",
  "value" : "http://test",
  "created" : "2016-11-30T09:53:09+0000",
  "updated" : "2016-11-30T09:53:09+0000"
}

Actual results:
Can be overriden 

Expected results:
Not allowed to override values for: baseurl


Additional info:

Comment 3 Tom McKay 2016-11-30 12:55:49 UTC
Why is this a bad thing? Are there not usecases for this, especially with custom (non-Red Hat) products with Sat-6?

Comment 4 John Sefler 2016-11-30 22:06:52 UTC
Starting in candlepin version 2.0.10-1, the restriction on overriding the baseurl has been lifted against a standalone candlepin server for the benefit of mirror lists in Satellite.

See https://trello.com/c/6IKbKppZ/7-work-with-satellite-team-to-design-out-mirror-lists-for-subscription-manager

See https://github.com/candlepin/candlepin/commit/bbba2dfc1ba44a16fef3d483caf4e7d4eaf63c10


Note You need to log in before you can comment on or make changes to this bug.