Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-23167

Reader role users are able to delete network ports in RHOSO, which violates expected read-only permissions.

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • None
    • rhos-18.0.13
    • neutron-operator
    • Neutron Quark 1
    • 1
    • Important

      The customer reported that users with the "reader" role in RHOSO are able to delete network ports, which contradicts the intended read-only nature of the role. This behavior has caused security and compliance concerns, preventing QA approval for deployments.{}

      The issue has been consistently reproduced across multiple environments — both default and non-default project setups — and no custom roles or policy overrides were found in the configurations.

              skaplons@redhat.com Slawomir Kaplonski
              rhn-support-pambre Parag Ambre
              rhos-dfg-networking-squad-neutron
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: