oauth controller calls are not protected
Bug #1231709 reported by
Steve Martinelli
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
Fix Released
|
High
|
Steve Martinelli |
Bug Description
It's open season for the oauth controllers, and anyone can call anything they want.
None of the controllers are protected. The policy.json file needs to be updated accordingly.
Changed in keystone: | |
milestone: | none → havana-rc1 |
importance: | Undecided → High |
Changed in keystone: | |
status: | Fix Committed → Fix Released |
Changed in keystone: | |
milestone: | havana-rc1 → 2013.2 |
To post a comment you must log in.
Fix proposed to branch: master /review. openstack. org/48534
Review: https:/