Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1746470

Summary: Horizon shouldn't allow users to attempt changing image disk format [osp13]
Product: Red Hat OpenStack Reporter: Jeremy <jmelvin>
Component: python-django-horizonAssignee: RHOS Maint <rhos-maint>
Status: CLOSED ERRATA QA Contact: Radomir Dopieralski <rdopiera>
Severity: low Docs Contact:
Priority: low    
Version: 13.0 (Queens)CC: athomas, jrist, rdopiera
Target Milestone: ---Keywords: Triaged, ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: python-django-horizon-13.0.2-7.el7ost Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1778128 (view as bug list) Environment:
Last Closed: 2020-03-10 11:25:01 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1778128    

Description Jeremy 2019-08-28 14:27:13 UTC
Description of problem: According to https://docs.openstack.org/glance/queens/admin/manage-images.html

After you upload an image, you cannot change it.

When users do try to change image disk format in horizon it bugs out with a permission denied error and auto logs out the user from horizon. 

Also error message appear in glance:
/var/log/containers/glance/api.log.1

2019-08-27 16:57:40.686 32 DEBUG glance.api.v2.images [req-63ee49b3-60f0-4164-b43f-6dd54cb618c4 efa2bf786215464e94f7dc5ceb077252 fe0579143bba47ae8501b5c6c7e80804 - default default] User not permitted to update image '2a8fd213-70a8-47ae-832f-ef84b0055d53' update /usr/lib/python2.7/site-packages/glance/api/v2/images.py:237
2019-08-27 16:57:40.688 32 INFO eventlet.wsgi.server [req-63ee49b3-60f0-4164-b43f-6dd54cb618c4 efa2bf786215464e94f7dc5ceb077252 fe0579143bba47ae8501b5c6c7e80804 - default default] 172.16.21.72 - - [27/Aug/2019 16:57:40] "PATCH /v2/images/2a8fd213-70a8-47ae-832f-ef84b0055d53 HTTP/1.1" 403 374 0.031469


Version-Release number of selected component (if applicable):
rpm -qa |grep horiz
python-django-horizon-13.0.1-4.el7ost.noarch
puppet-horizon-12.4.0-1.el7ost.noarch


How reproducible:
100%

Steps to Reproduce:
1. Create image
2. click images> Edit Image > change format dropdown from raw to qcow2 > click update image.
3.

Actual results:
logs you out of horizon


Expected results:
No option to edit image disk format should be available to prevent this buggy-ness

Additional info:
Also see the same in osp14, however it doesn't auto log out the user; so not quite as ugly

Comment 2 Radomir Dopieralski 2019-08-29 08:03:14 UTC
I'm setting this to priority low, because it doesn't prevent the users from performing any operations or doing their work.

Comment 6 errata-xmlrpc 2020-03-10 11:25:01 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:0763