+1
From: Adam Young
Sent: Friday, September 04, 2015 7:43:08 PM
To: openstack-dev@lists.openstack.org
Subject: Re: [openstack-dev] This is what disabled-by-policy should look like
to the user
On 09/04/2015 10:04 AM, Monty Taylor wrote:
> mordred@camelot:~$
On 09/06/2015 03:31 PM, Duncan Thomas wrote:
On 5 Sep 2015 05:47, "Adam Young" > wrote:
> Then let my Hijack:
>
> Policy is still broken. We need the pieces of Dynamic policy.
>
> I am going to call for a cross project policy discussion for the
On 5 Sep 2015 05:47, "Adam Young" wrote:
> Then let my Hijack:
>
> Policy is still broken. We need the pieces of Dynamic policy.
>
> I am going to call for a cross project policy discussion for the upcoming
summit. Please, please, please all the projects attend. The
On Fri, Sep 4, 2015 at 8:04 AM, Monty Taylor wrote:
> mordred@camelot:~$ neutron net-create test-net-mt
> Policy doesn't allow create_network to be performed.
>
> Thank you neutron. Excellent job.
>
> Here's what that looks like at the REST layer:
>
> DEBUG:
mordred@camelot:~$ neutron net-create test-net-mt
Policy doesn't allow create_network to be performed.
Thank you neutron. Excellent job.
Here's what that looks like at the REST layer:
DEBUG: keystoneclient.session RESP: [403] date: Fri, 04 Sep 2015
13:55:47 GMT connection: close content-type:
On 09/04/2015 10:55 AM, Morgan Fainberg wrote:
On Sep 4, 2015, at 07:04, Monty Taylor
wrote:
mordred@camelot:~$ neutron net-create test-net-mt Policy doesn't
allow create_network to be performed.
Thank you neutron. Excellent job.
Here's what that looks like at the
> On Sep 4, 2015, at 07:04, Monty Taylor wrote:
>
> mordred@camelot:~$ neutron net-create test-net-mt
> Policy doesn't allow create_network to be performed.
>
> Thank you neutron. Excellent job.
>
> Here's what that looks like at the REST layer:
>
> DEBUG:
On 2015-09-04 12:50 PM, Monty Taylor wrote:
> On 09/04/2015 10:55 AM, Morgan Fainberg wrote:
>>
>> Obviously the translation of errors
>> would be more difficult if the enforcer is generating messages.
>
> The type: "PolicyNotAuthorized" is a good general key. Also - even
> though the command I
On Fri, Sep 4, 2015 at 11:35 AM, Mathieu Gagné wrote:
> On 2015-09-04 12:50 PM, Monty Taylor wrote:
> > On 09/04/2015 10:55 AM, Morgan Fainberg wrote:
> >>
> >> Obviously the translation of errors
> >> would be more difficult if the enforcer is generating messages.
> >
> >
On Fri, Sep 4, 2015 at 10:35 AM, Mathieu Gagné wrote:
> On 2015-09-04 12:50 PM, Monty Taylor wrote:
> > On 09/04/2015 10:55 AM, Morgan Fainberg wrote:
> >>
> >> Obviously the translation of errors
> >> would be more difficult if the enforcer is generating messages.
> >
> >
On 09/04/2015 01:42 PM, John Griffith wrote:
On Fri, Sep 4, 2015 at 11:35 AM, Mathieu Gagné wrote:
On 2015-09-04 12:50 PM, Monty Taylor wrote:
On 09/04/2015 10:55 AM, Morgan Fainberg wrote:
Obviously the translation of errors
would be more difficult if the enforcer is
On 2015-09-04 2:41 PM, Monty Taylor wrote:
> On 09/04/2015 01:42 PM, John Griffith wrote:
>>
>> Is no good? You would like to see "less" in the output; like just the
>> command name itself and "Policy doesn't allow"?
>>
>> To Mathieu's point, fair statement WRT the visibility of the policy name.
On 09/04/2015 10:04 AM, Monty Taylor wrote:
mordred@camelot:~$ neutron net-create test-net-mt
Policy doesn't allow create_network to be performed.
Thank you neutron. Excellent job.
Here's what that looks like at the REST layer:
DEBUG: keystoneclient.session RESP: [403] date: Fri, 04 Sep 2015
13 matches
Mail list logo