glance/glance/tests/etc
Rick Bartra d2cc0dc566 Add Policy enforcement for several Metadata Definition delete APIs
Several Metadata Definition delete APIs do not have RBAC. This
patchset add policy enforcment to the following APIs:

    - `Delete namespace`
    - `Delete object`
    - `Remove resource type association`
    - `Remove property definition`
    - `Delete tag definition`
    - `Delete all tag definitions`

The following actions are enforce and added to the policy.json:

    - `delete_metadef_namespace`
    - `delete_metadef_object`
    - `remove_metadef_resource_type_association`
    - `remove_metadef_property`
    - `delete_metadef_tag`
    - `delete_metadef_tags`

Most other APIs have policy enforcement, so the ones above should as
well. Without adding policy enforcement for the above APIs, all roles
can peform the delete APIs noted above.

Change-Id: I8cd6eb26b0d3401fa4667384c31e4c56d838d42b
Closes-Bug: #1782840
Co-Authored-By: julian.sy@att.com
2020-04-06 14:47:05 +00:00
..
glance-swift.conf Remove user and key from location in swift 2014-06-24 12:13:26 +05:30
policy.json Add Policy enforcement for several Metadata Definition delete APIs 2020-04-06 14:47:05 +00:00
property-protections-policies.conf Check first matching rule for protected properties 2014-01-22 17:41:10 +00:00
property-protections.conf Make properties roles check case-insensitive 2015-06-03 08:30:21 +00:00
schema-image.json Use container_format and disk_format as-is in v2 2012-08-10 14:09:49 -07:00