Return-Path: X-Original-To: apmail-cloudstack-issues-archive@www.apache.org Delivered-To: apmail-cloudstack-issues-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id B53081044C for ; Wed, 9 Oct 2013 00:11:42 +0000 (UTC) Received: (qmail 29846 invoked by uid 500); 9 Oct 2013 00:11:42 -0000 Delivered-To: apmail-cloudstack-issues-archive@cloudstack.apache.org Received: (qmail 29808 invoked by uid 500); 9 Oct 2013 00:11:42 -0000 Mailing-List: contact issues-help@cloudstack.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@cloudstack.apache.org Delivered-To: mailing list issues@cloudstack.apache.org Received: (qmail 29687 invoked by uid 500); 9 Oct 2013 00:11:42 -0000 Delivered-To: apmail-incubator-cloudstack-issues@incubator.apache.org Received: (qmail 29610 invoked by uid 99); 9 Oct 2013 00:11:42 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 09 Oct 2013 00:11:42 +0000 Date: Wed, 9 Oct 2013 00:11:42 +0000 (UTC) From: "Jessica Wang (JIRA)" To: cloudstack-issues@incubator.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Commented] (CLOUDSTACK-3364) [UI] normal users are not allowed to edit their own iso MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/CLOUDSTACK-3364?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13789856#comment-13789856 ] Jessica Wang commented on CLOUDSTACK-3364: ------------------------------------------ Nitin, I have questions about registerIso API and updateIsoPermissions API. (1) A normal user is allowed to specify isextractable property when registering an ISO (through registerIso API), but NOT allowed to update isextractable property when updating an ISO (through updateIsoPermissions API). Is this by design or it's just an API bug? (2) A normal user is NOT allowed to specify isfeatured property when registering an ISO (through registerIso API), but allowed to update isfeatured property when updating an ISO (through updateIsoPermissions API)? Is this by design or it's just an API bug? Jessica > [UI] normal users are not allowed to edit their own iso > ------------------------------------------------------- > > Key: CLOUDSTACK-3364 > URL: https://issues.apache.org/jira/browse/CLOUDSTACK-3364 > Project: CloudStack > Issue Type: Bug > Security Level: Public(Anyone can view this level - this is the default.) > Components: UI > Affects Versions: 4.2.0 > Reporter: shweta agarwal > Assignee: Jessica Wang > Fix For: 4.2.1 > > > Repro steps: > 1.Create a domain > 2.create a account under that domain > 3.create a ISO as a account under the non root domain > 4.Edit the ISO > BUg : > gets message: > Only ROOT admins are allowed to modify this attribute. > API: > http://10.147.38.141:8080/client/api?command=updateIsoPermissions&response=json&sessionkey=8rczMjm4sfljFOEi6dL2xT631sc%3D&id=2b8c87a0-4325-418d-80af-ce6f691edcd7&zoneid=bfdf7ac5-16c3-491e-aabd-f7ad696612b8&ispublic=false&isfeatured=false&isextractable=false&_=1372941865923 > response: > { "updateisopermissionsresponse" : {"uuidList":[],"errorcode":431,"cserrorcode":4350,"errortext":"Only ROOT admins are allowed to modify this attribute."} } > This may be because in case of edit ISO we show extractable and featured field as editable to normal user , which normal user is not allowed to do and api passes these as parameters > In case of template these fields are shown as non editable hence API passed does not contain isfeatured and isextractable fields -- This message was sent by Atlassian JIRA (v6.1#6144)