Re: [openstack-dev] [nova] Policy rules are killed by the context admin check

2015-04-27 Thread Sylvain Bauza
Le 23/04/2015 09:10, Sylvain Bauza a écrit : Le 23 avr. 2015 04:49, "Alex Xu" > a écrit : > > > > 2015-04-23 6:55 GMT+08:00 Matt Riedemann >: >> >> >> >> On 4/22/2015 8:32 AM, Sylvain Bauza wrote: >>> >>> Hi, >>> >>> By discussing

Re: [openstack-dev] [nova] Policy rules are killed by the context admin check

2015-04-23 Thread Sylvain Bauza
Le 23 avr. 2015 04:49, "Alex Xu" a écrit : > > > > 2015-04-23 6:55 GMT+08:00 Matt Riedemann : >> >> >> >> On 4/22/2015 8:32 AM, Sylvain Bauza wrote: >>> >>> Hi, >>> >>> By discussing on a specific bug [1], I just discovered that the admin >>> context check which was done at the DB level has been m

Re: [openstack-dev] [nova] Policy rules are killed by the context admin check

2015-04-22 Thread Alex Xu
2015-04-23 6:55 GMT+08:00 Matt Riedemann : > > > On 4/22/2015 8:32 AM, Sylvain Bauza wrote: > >> Hi, >> >> By discussing on a specific bug [1], I just discovered that the admin >> context check which was done at the DB level has been moved to the API >> level thanks to the api-policy-v3 blueprint

Re: [openstack-dev] [nova] Policy rules are killed by the context admin check

2015-04-22 Thread Morgan Fainberg
On Wednesday, April 22, 2015, Matt Riedemann wrote: > > > On 4/22/2015 8:32 AM, Sylvain Bauza wrote: > >> Hi, >> >> By discussing on a specific bug [1], I just discovered that the admin >> context check which was done at the DB level has been moved to the API >> level thanks to the api-policy-v3

Re: [openstack-dev] [nova] Policy rules are killed by the context admin check

2015-04-22 Thread Matt Riedemann
On 4/22/2015 8:32 AM, Sylvain Bauza wrote: Hi, By discussing on a specific bug [1], I just discovered that the admin context check which was done at the DB level has been moved to the API level thanks to the api-policy-v3 blueprint [2] That behaviour still leads to a bug if the operator wants

[openstack-dev] [nova] Policy rules are killed by the context admin check

2015-04-22 Thread Sylvain Bauza
Hi, By discussing on a specific bug [1], I just discovered that the admin context check which was done at the DB level has been moved to the API level thanks to the api-policy-v3 blueprint [2] That behaviour still leads to a bug if the operator wants to change an endpoint policy by leaving i