Set default policy for "volume:get"
Currently, there is no policy check defined for "volume:get", so everyone can get another tenant's volume detail by UUID. It's necessary to set policy to "rule:admin_or_owner" for "volume:get" by default. Change-Id: Iefdf7e5703a28856b20d97a885267c01bed6bbb4 Closes-bug: #1475422
This commit is contained in:
parent
34f07c635b
commit
5a4f399d6c
@ -7,7 +7,7 @@
|
||||
|
||||
"volume:create": "",
|
||||
"volume:delete": "",
|
||||
"volume:get": "",
|
||||
"volume:get": "rule:admin_or_owner",
|
||||
"volume:get_all": "",
|
||||
"volume:get_volume_metadata": "",
|
||||
"volume:get_volume_admin_metadata": "rule:admin_api",
|
||||
|
Loading…
x
Reference in New Issue
Block a user