]> review.fuel-infra Code Review - openstack-build/neutron-build.git/commitdiff
Disallow non-admin to specify binding:profile
authorAkihiro MOTOKI <motoki@da.jp.nec.com>
Thu, 22 Aug 2013 02:34:43 +0000 (11:34 +0900)
committerAkihiro MOTOKI <motoki@da.jp.nec.com>
Thu, 22 Aug 2013 02:36:58 +0000 (11:36 +0900)
Change-Id: Iefa4b251f3b0a373fb9b2b7d576e14d58afece59
Fixes-Bug: #1214873

etc/policy.json

index 6310e2b136ffbf2d3741e4d5bf2f75c733a0227c..78dd1e4c7914919fa81b3fd07d083ea9ec74b7c7 100644 (file)
@@ -44,6 +44,7 @@
     "create_port:fixed_ips": "rule:admin_or_network_owner",
     "create_port:port_security_enabled": "rule:admin_or_network_owner",
     "create_port:binding:host_id": "rule:admin_only",
+    "create_port:binding:profile": "rule:admin_only",
     "create_port:mac_learning_enabled": "rule:admin_or_network_owner",
     "get_port": "rule:admin_or_owner",
     "get_port:queue_id": "rule:admin_only",
@@ -55,6 +56,7 @@
     "update_port:fixed_ips": "rule:admin_or_network_owner",
     "update_port:port_security_enabled": "rule:admin_or_network_owner",
     "update_port:binding:host_id": "rule:admin_only",
+    "update_port:binding:profile": "rule:admin_only",
     "update_port:mac_learning_enabled": "rule:admin_or_network_owner",
     "delete_port": "rule:admin_or_owner",