apache / apache/cloudstack

Global setting to disallow domain admin to change domain and account settings

未关闭
#7,296 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
archive status:stale type:config
主要语言
Java
星标
3.1k
派生
1.4k
平均合并
6 天 19 小时
30 天内合并 PR
32

描述

##### ISSUE TYPE

* Bug Report

##### COMPONENT NAME

~~~
UI, Permissions, Access Controll
~~~

##### CLOUDSTACK VERSION

~~~
4.17 onwards
~~~

##### SUMMARY

The https://github.com/apache/cloudstack/pull/4339 pull request allows CloudStack's domain admins to change their domains configurations. This option gives domain admins power to abuse CloudStack system IPs, create public templates, share their templates with other domains, and many more unwanted effects to the environments even though the root admin disallow these actions in the first place.

| Domain level settings |
|:------------------------------------------:|
| account.allow.expose.host.hostname |
| allow.public.user.templates |
| preferred.storage.pool |
|share.public.templates.with.other.domains |
| use.system.public.ips |

As of now there isn't a global setting to revert this changes. I have the following suggestions let me know what do you think.

1. Add a global setting to override this behaviour.
2. Move these setting to global level so domain admins can't change them.
3. Give priority to the global level settings, so if domain admins override a setting.

##### STEPS TO REPRODUCE

~~~
1. Login as a root admin
2. Configure the domain
3. Log out
4. Login as a domain admin
5. Configure the domain
~~~

##### EXPECTED RESULTS

~~~
Root admin configurations are **NOT** overridden.
~~~

##### ACTUAL RESULTS

~~~
Root admin configurations are overridden.
~~~

贡献指南

打开贡献指南

调研方向

首先追踪域配置的 UI、权限和访问控制流程,重点关注列出的设置以及 root-admin/domain-admin 的步骤。确定预期的全局覆盖行为,然后验证 root-admin 的配置不能被 domain admins 覆盖。

由索引模型根据 Issue 内容生成。

评估

技术栈
java
领域
authorization, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。