You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@cloudstack.apache.org by "shweta agarwal (JIRA)" <ji...@apache.org> on 2013/07/17 12:46:48 UTC

[jira] [Reopened] (CLOUDSTACK-3364) normal users are not allowed to edit their own iso

     [ https://issues.apache.org/jira/browse/CLOUDSTACK-3364?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

shweta agarwal reopened CLOUDSTACK-3364:
----------------------------------------


Have you read my entire comment in the bug .
I have stated clearly that

This may be because in case of edit ISO we show extractable and featured field as editable to normal user , which normal user is not allowed to do and api passes these as parameters

In case of template these fields are shown as non editable hence API passed does not contain isfeatured and isextractable fields 



I think normal user should be at least allowed to change the name of his own ISO; the way we allowed in case of templates


                
> normal users are not allowed to edit their own iso
> --------------------------------------------------
>
>                 Key: CLOUDSTACK-3364
>                 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-3364
>             Project: CloudStack
>          Issue Type: Bug
>      Security Level: Public(Anyone can view this level - this is the default.) 
>          Components: API, ISO, UI
>    Affects Versions: 4.2.0
>            Reporter: shweta agarwal
>            Assignee: Nitin Mehta
>             Fix For: 4.2.0
>
>
> Repro steps:
> 1.Create a domain
> 2.create a account under that domain
> 3.create a ISO as a account under the non root domain
> 4.Edit the ISO
> BUg :
> gets message: 
> Only ROOT admins are allowed to modify this attribute.
> API:
> http://10.147.38.141:8080/client/api?command=updateIsoPermissions&response=json&sessionkey=8rczMjm4sfljFOEi6dL2xT631sc%3D&id=2b8c87a0-4325-418d-80af-ce6f691edcd7&zoneid=bfdf7ac5-16c3-491e-aabd-f7ad696612b8&ispublic=false&isfeatured=false&isextractable=false&_=1372941865923
> response:
> { "updateisopermissionsresponse" : {"uuidList":[],"errorcode":431,"cserrorcode":4350,"errortext":"Only ROOT admins are allowed to modify this attribute."} }
> This may be because in case of edit ISO we show  extractable and featured field as editable to normal user , which normal user is not allowed to do  and api passes these as parameters
> In case of template these fields are shown as non editable hence API passed does not contain isfeatured and isextractable fields

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira