Public bug reported: The default policy for os-server-tags listed here (https://github.com/openstack/nova/blob/master/etc/nova/policy.json#L448-L453) allow all users to do any CRUD operations on all server tags. This should be limited down to only admin_or_owner.
** Affects: nova Importance: Medium Assignee: Ryan Rossiter (rlrossit) Status: In Progress ** Tags: api policy tags -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1581203 Title: Default policy allows unrestricted CRUD on os-server-tags Status in OpenStack Compute (nova): In Progress Bug description: The default policy for os-server-tags listed here (https://github.com/openstack/nova/blob/master/etc/nova/policy.json#L448-L453) allow all users to do any CRUD operations on all server tags. This should be limited down to only admin_or_owner. To manage notifications about this bug go to: https://bugs.launchpad.net/nova/+bug/1581203/+subscriptions -- Mailing list: https://launchpad.net/~yahoo-eng-team Post to : yahoo-eng-team@lists.launchpad.net Unsubscribe : https://launchpad.net/~yahoo-eng-team More help : https://help.launchpad.net/ListHelp