Bug 1460145 - [ursxF5mB]The message of forbidden without assign permission to create templateinstance could be more friendly
Summary: [ursxF5mB]The message of forbidden without assign permission to create templa...
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Service Broker
Version: 3.6.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 3.7.0
Assignee: Jim Minter
QA Contact: XiuJuan Wang
Depends On:
TreeView+ depends on / blocked
Reported: 2017-06-09 09:03 UTC by XiuJuan Wang
Modified: 2017-11-28 21:56 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
The error message returned when a user does not have permission to modify a TemplateInstance was improved.
Clone Of:
Last Closed: 2017-11-28 21:56:55 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:3188 0 normal SHIPPED_LIVE Moderate: Red Hat OpenShift Container Platform 3.7 security, bug, and enhancement update 2017-11-29 02:34:54 UTC

Description XiuJuan Wang 2017-06-09 09:03:06 UTC
Description of problem:
The message of forbidden without assign permission to create templateinstance is urgly.

Version-Release number of selected component (if applicable):

oc v3.6.100
kubernetes v1.6.1+5115d708d7
features: Basic-Auth GSSAPI Kerberos SPNEGO

Server https://***:443
openshift v3.6.100
kubernetes v1.6.1+5115d708d7

How reproducible:

Steps to Reproduce:
1.Enable template service broker by admin
2.Create a templateinstance with requester.username that is not the requester user

Actual results:
Show below forbidden message:
The TemplateInstance "instance1" is invalid: spec.requester.username: Forbidden: impersonation forbidden: templateinstances.template.openshift.io "" is forbidden: User "xiuwang" cannot "assign" "templateinstances.template.openshift.io" with name "" in project "xiu3"

Expected results:
The forbidden message should be more friendly

Additional info:

Comment 1 Jim Minter 2017-06-09 10:04:15 UTC

Comment 2 XiuJuan Wang 2017-06-14 02:40:59 UTC
This issue has fixed in [1]
The forbidden info is more friendly.

The TemplateInstance "instance1" is invalid: spec.requester.username: Forbidden: you do not have permission to set username

Server https://***:8443
openshift v3.6.106
kubernetes v1.6.1+5115d708d7

Will move to verified after bug status change to on_qa

Comment 4 XiuJuan Wang 2017-07-06 03:22:58 UTC
Test with oc version v3.6.135, this issue has been fixed, move this bug to verified.

Comment 8 errata-xmlrpc 2017-11-28 21:56:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.