Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-26861

neutron-fwaas don't allow admin users to attach fw group to the port from diffent project

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • openstack-neutron
    • None
    • Moderate

      Even admin user who is by default allowed to see and modify fw groups from all projects can't attach fw group to the router's port which belongs to the other project then project owning fw group itself. It is like that because of the check https://github.com/openstack/neutron-fwaas/blob/master/neutron_fwaas/services/firewall/fwaas_plugin_v2.py#L167 which should probably be skipped if context.is_admin is True.

              skaplons@redhat.com Slawomir Kaplonski
              skaplons@redhat.com Slawomir Kaplonski
              rhos-dfg-networking-squad-neutron
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: