Project

General

Profile

Actions

Bug #63791

closed

RGW: a subuser with no permission can still list buckets and create buckets

Added by Huy Nguyen 5 months ago. Updated 7 days ago.

Status:
Resolved
Priority:
Normal
Target version:
-
% Done:

0%

Source:
Tags:
Backport:
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Hi,
I just found out a subuser with no permission can still list buckets and create buckets. Is it a bug or a feature? Because as I know, this issue has been there for a long time

Actions #1

Updated by Casey Bodley 5 months ago

is this with s3? subusers were invented for swift, so the interactions with s3 have never been well-defined

Actions #2

Updated by hoan nv 5 months ago

Casey Bodley wrote:

is this with s3? subusers were invented for swift, so the interactions with s3 have never been well-defined

I have same problem.

From 14 ceph versions, ceph rgw can assign permission to s3 subuser. It is a helpful feature.

So if this feature can improve, it will be great.

Actions #3

Updated by Shreyansh Sancheti 5 months ago

  • Assignee set to Shreyansh Sancheti
Actions #4

Updated by Shreyansh Sancheti 4 months ago

  • Status changed from New to Need More Info

Casey Bodley wrote:

is this with s3? subusers were invented for swift, so the interactions with s3 have never been well-defined

So a subuser with no permission should be able to do what operations? I mean it should not be able to list buckets and create new ones is that the request?.

Actions #5

Updated by hoan nv 4 months ago

Shreyansh Sancheti wrote:

Casey Bodley wrote:

is this with s3? subusers were invented for swift, so the interactions with s3 have never been well-defined

So a subuser with no permission should be able to do what operations? I mean it should not be able to list buckets and create new ones is that the request?.

subuser with no permission should not able to do anything.

Actions #6

Updated by Shreyansh Sancheti 4 months ago

  • Status changed from Need More Info to In Progress
Actions #7

Updated by Shreyansh Sancheti about 2 months ago

  • Pull request ID set to 55661
Actions #8

Updated by Daniel Gryniewicz 28 days ago

  • Status changed from In Progress to Fix Under Review
Actions #9

Updated by Casey Bodley 22 days ago

  • Status changed from Fix Under Review to Resolved
Actions #10

Updated by hoan nv 22 days ago

This commit can be backported to quincy reef ?

Actions #11

Updated by Pierre Riteau 7 days ago

I believe this is also an issue for subusers with read permissions: they can still create buckets (at least on Quincy 17.2.6).

Actions

Also available in: Atom PDF