Browse Source

Disallow regular user to update firewall's shared attribute

Shared firewalls should only be operable by  admins.
Currently only admin can provide shared attribute at firewall creation,
so update_firewall should be consistent with that as well.

Change-Id: I093743514637824207b375d724404d51f778d012
Closes-Bug: #1323322
changes/26/309326/1
Eugene Nikanorov 8 years ago
parent
commit
c05dd7f72a
  1. 1
      etc/policy.json

1
etc/policy.json

@ -70,6 +70,7 @@
"create_firewall:shared": "rule:admin_only",
"get_firewall:shared": "rule:admin_only",
"update_firewall": "rule:admin_or_owner",
"update_firewall:shared": "rule:admin_only",
"delete_firewall": "rule:admin_or_owner",
"create_firewall_policy": "",

Loading…
Cancel
Save