Global setting to disallow domain admin to change domain and account settings
- Linguagem predominante
- Java
- Estrelas
- 3.1k
- Forks
- 1.4k
- Merge médio
- 6d 19h
- PRs com merge (30d)
- 32
Descrição
##### ISSUE TYPE
* Bug Report
##### COMPONENT NAME
~~~
UI, Permissions, Access Controll
~~~
##### CLOUDSTACK VERSION
~~~
4.17 onwards
~~~
##### SUMMARY
The https://github.com/apache/cloudstack/pull/4339 pull request allows CloudStack's domain admins to change their domains configurations. This option gives domain admins power to abuse CloudStack system IPs, create public templates, share their templates with other domains, and many more unwanted effects to the environments even though the root admin disallow these actions in the first place.
| Domain level settings |
|:------------------------------------------:|
| account.allow.expose.host.hostname |
| allow.public.user.templates |
| preferred.storage.pool |
|share.public.templates.with.other.domains |
| use.system.public.ips |
As of now there isn't a global setting to revert this changes. I have the following suggestions let me know what do you think.
1. Add a global setting to override this behaviour.
2. Move these setting to global level so domain admins can't change them.
3. Give priority to the global level settings, so if domain admins override a setting.
##### STEPS TO REPRODUCE
~~~
1. Login as a root admin
2. Configure the domain
3. Log out
4. Login as a domain admin
5. Configure the domain
~~~
##### EXPECTED RESULTS
~~~
Root admin configurations are **NOT** overridden.
~~~
##### ACTUAL RESULTS
~~~
Root admin configurations are overridden.
~~~
Guia de contribuição
Direção de pesquisa
Comece rastreando o fluxo de UI, permissões e controle de acesso para a configuração do domínio, com foco nas configurações listadas e nas etapas de root-admin/domain-admin. Determine qual comportamento de substituição global é pretendido e, em seguida, verifique se as configurações de root-admin não podem ser substituídas por administradores de domínio.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- java
- Domínio
- authorization, security
- Tipo de issue
- Funcionalidade
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Status de atividade
- Estagnada
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 35/100