manila leaks information about volume existance of other projects
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Shared File Systems Service (Manila) |
New
|
Undecided
|
Unassigned |
Bug Description
Description of problem:
manilla leaks information about volume existance of other projects
$ manila list
+------
| ID
| Name | [...] | Is Public | [...] |
+------
| a57cb81d-
| [...] |
+------
$ manila show b0758fbd-
ERROR: Policy doesn't allow share:get to be performed. (HTTP 403) (Request-ID: req-50e432e1-
b463-416b-
$ manila show b0758fbd-
ERROR: No share with a name or ID of 'b0758fbd-
In both cases the response should be that the volume doesn't exist, a user should not be able to find out if a volume exists in another project.