Uploaded image for project: 'Hybrid Cloud Console'
  1. Hybrid Cloud Console
  2. RHCLOUD-34930

In order to reduce effort and prevent relations inconsistency, remove /policies/ endpoints

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • Unset
    • CRCPLAN-232 - Kessel | PRBAC v2 Service Provider Migration Enablement (Internal)
    • None
    • Access & Management Sprint 95, Access & Management Sprint 95

      These endpoints need either to be removed, or they need to incorporate dual-write logic to the Relations API in Kessel.

      Since they were deprecated long ago, we prefer to remove them and save ourselves the trouble.

      If they are left and still usable, their use can lead to permanently inconsistent data between Relations and RBAC. For example, if someone (e.g. a bad actor or by mistake) removed a role from a group in RBAC, it would still have access but it would not appear as if it did.

              rh-ee-zhzeng Jay Zeng
              rhit-ahenning Alec Henninger
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: