Project

General

Profile

Actions

Bug #1115

closed

rgw allows users to "give away" s3 objects

Added by Colin McCabe almost 13 years ago. Updated over 6 years ago.

Status:
Resolved
Priority:
High
Assignee:
Target version:
-
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

The Rados gateway should not allow the owner of an object to be changed through a PUTACL operation. Amazon doesn't allow this. Unfortunately, RGW currently does. This could create all sorts of trouble with billing-- like creating tons of files and giving them away to some sucker who will then have to pay the storage costs.

Actions

Also available in: Atom PDF