Bug 1467692 - credentials not required when adding provider using the REST API
Summary: credentials not required when adding provider using the REST API
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: API
Version: 5.8.0
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: GA
: 5.9.0
Assignee: Jillian Tullo
QA Contact: Martin Kourim
URL:
Whiteboard: api:rest:provider
: 1467694 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-07-04 15:40 UTC by Martin Kourim
Modified: 2019-08-06 20:05 UTC (History)
6 users (show)

Fixed In Version: 5.9.0.1
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-03-01 13:14:47 UTC
Category: ---
Cloudforms Team: ---
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0380 0 normal SHIPPED_LIVE Moderate: Red Hat CloudForms security, bug fix, and enhancement update 2018-03-01 18:37:12 UTC

Description Martin Kourim 2017-07-04 15:40:38 UTC
Description of problem:
When adding providers using UI, specifying credentials is required. Using the REST API it's possible to add providers without specifying credentials.

This behavior is documented in <http://manageiq.org/docs/reference/latest/api/appendices/resource_attributes.html#providers>, but it's inconsistent with how providers are added using UI.

Comment 2 Gregg Tanzillo 2017-07-06 14:28:37 UTC
*** Bug 1467694 has been marked as a duplicate of this bug. ***

Comment 3 Jillian Tullo 2017-07-07 18:31:45 UTC
PR: https://github.com/ManageIQ/manageiq/pull/15528

Comment 4 Satoe Imaishi 2017-09-28 19:16:07 UTC
PR: https://github.com/ManageIQ/manageiq-api/pull/16

Comment 7 Martin Kourim 2017-10-23 16:44:58 UTC
It's still possible to add provider without specifying credentials. Having empty "connection_configurations" or "credentials" is enough for the request to succeed.

Comment 8 Jillian Tullo 2017-10-24 15:10:16 UTC
I think that for this part, we may want to create a separate RFE. There are a lot of providers, and specific logic about what should be in the "connection_configurations" or "credentials" should really be done within the provider itself, not within the API controller. Does that work?

Comment 9 Martin Kourim 2017-10-24 15:21:55 UTC
Makes sense, I agree. I'm marking this one as verified then.

Comment 12 errata-xmlrpc 2018-03-01 13:14:47 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:0380


Note You need to log in before you can comment on or make changes to this bug.