Domain admin cannot manage user, group and domain in own domain

Bug #1600195 reported by Kenji Ishii
22
This bug affects 4 people
Affects Status Importance Assigned to Milestone
OpenStack Dashboard (Horizon)
In Progress
Undecided
Yaguang Tang

Bug Description

When a user who have a privilege as a domain admin logged in with domain scoped token, he cannot do some operation about user, group.
Because in this case these menu are not displayed (In this case, we assume that keystone v3 policy file (policy.v3cloudsample.json) is used).
Originally, this user should be able to create/delete users.

Actually, domain admin cannot do actions below.
 - create user
 - delete user (from table action)
 - delete project (from table action)
 - create group
 - delete group (from table action)
 - add member
 - remove member

Tags: keystone
Kenji Ishii (ken-ishii)
Changed in horizon:
assignee: nobody → Kenji Ishii (ken-ishii)
Kenji Ishii (ken-ishii)
description: updated
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to horizon (master)

Fix proposed to branch: master
Review: https://review.openstack.org/339487

Changed in horizon:
status: New → In Progress
Kenji Ishii (ken-ishii)
summary: - Domain admin cannot create/delete user
+ Domain admin cannot manage user, group and domain in own domain
description: updated
Changed in horizon:
assignee: Kenji Ishii (ken-ishii) → Yaguang Tang (heut2008)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on horizon (master)

Change abandoned by Ivan Kolodyazhny (<email address hidden>) on branch: master
Review: https://review.openstack.org/339487
Reason: This review is > 4 months without comment, and failed Jenkins the last time it was checked. We are abandoning this for now. Feel free to reactivate the review by pressing the restore button and leaving a 'recheck' comment to get fresh test results.

Akihiro Motoki (amotoki)
tags: added: keystone
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.