Public bug reported: The attached screenshots are from the 'network topology' horizon panel. I'm running as a user with restricted read-only rights, and yet the UI suggests that I delete VMs (which I am not allowed to delete) and networks (which I am not allowed to delete.)
This isn't a security issue since the neutron and nova APIs won't actually allow the deletion. Still, the UI wrong and alarming. We need policy checks around these buttons. ** Affects: horizon Importance: Undecided Status: New ** Attachment added: "delete_network.png" https://bugs.launchpad.net/bugs/2104173/+attachment/5867239/+files/delete_network.png -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://bugs.launchpad.net/bugs/2104173 Title: network topology UI too enthusiastic about deletions Status in OpenStack Dashboard (Horizon): New Bug description: The attached screenshots are from the 'network topology' horizon panel. I'm running as a user with restricted read-only rights, and yet the UI suggests that I delete VMs (which I am not allowed to delete) and networks (which I am not allowed to delete.) This isn't a security issue since the neutron and nova APIs won't actually allow the deletion. Still, the UI wrong and alarming. We need policy checks around these buttons. To manage notifications about this bug go to: https://bugs.launchpad.net/horizon/+bug/2104173/+subscriptions -- Mailing list: https://launchpad.net/~yahoo-eng-team Post to : yahoo-eng-team@lists.launchpad.net Unsubscribe : https://launchpad.net/~yahoo-eng-team More help : https://help.launchpad.net/ListHelp