Add a configuration option so that horizon can be deployed to enforce scope
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| OpenStack Dashboard (Horizon) |
Triaged
|
High
|
Akihiro Motoki | ||
Bug Description
Now that keystone supports system-scope as well as default roles, several upstream OpenStack services are updating their default policies to be more secure [0].
Horizon may need to understand how these services are configured via policy to present the proper panels to certain users (e.g., should the admin panels be presented to project-admins modeling the old behavior or should they only be presented to system-users?)
This bug is to track the work for horizon to evaluate the configuration changes necessary to deploy secure RBAC. This topic was discussed during the Xena PTG [1].
[0] Using system-scope to fix https:/
[1] https:/
| description: | updated |
| Changed in horizon: | |
| importance: | Undecided → High |
| status: | New → Triaged |
| Changed in horizon: | |
| assignee: | nobody → Akihiro Motoki (amotoki) |
