*** yingjun has joined #openstack-horizon | 00:10 | |
*** ducttape_ has quit IRC | 00:35 | |
*** yingwei has joined #openstack-horizon | 00:37 | |
*** ducttape_ has joined #openstack-horizon | 00:38 | |
*** ducttape_ has quit IRC | 00:38 | |
*** ducttape_ has joined #openstack-horizon | 00:43 | |
*** Pavo has joined #openstack-horizon | 00:50 | |
*** Pavo has quit IRC | 00:54 | |
*** shuyingya has joined #openstack-horizon | 00:54 | |
*** gyee has quit IRC | 00:57 | |
*** yingwei has quit IRC | 00:58 | |
*** shuyingya has quit IRC | 01:01 | |
*** aortega has quit IRC | 01:05 | |
*** zhenguo has joined #openstack-horizon | 01:19 | |
*** efitzgerald has joined #openstack-horizon | 01:19 | |
*** shuyingya has joined #openstack-horizon | 01:24 | |
*** shuyingya has quit IRC | 01:24 | |
*** MasterOfBugs has quit IRC | 01:43 | |
*** yingwei has joined #openstack-horizon | 01:49 | |
*** efitzgerald has quit IRC | 01:57 | |
*** zhurong has joined #openstack-horizon | 02:02 | |
*** zhugaoxiao has quit IRC | 02:10 | |
*** zhurong has quit IRC | 02:18 | |
*** zul has quit IRC | 02:19 | |
*** ducttape_ has quit IRC | 02:28 | |
*** dave-mccowan has quit IRC | 02:36 | |
*** dave-mcc_ has joined #openstack-horizon | 02:44 | |
*** zhurong has joined #openstack-horizon | 02:44 | |
*** chlong has joined #openstack-horizon | 02:48 | |
*** ducttape_ has joined #openstack-horizon | 02:53 | |
*** ducttape_ has quit IRC | 02:53 | |
*** ducttape_ has joined #openstack-horizon | 02:59 | |
*** ducttape_ has quit IRC | 03:12 | |
*** mine0901 has joined #openstack-horizon | 03:14 | |
*** ducttape_ has joined #openstack-horizon | 03:18 | |
*** ducttape_ has quit IRC | 03:22 | |
*** dave-mcc_ has quit IRC | 03:24 | |
*** ratailor has joined #openstack-horizon | 03:39 | |
*** ratailor_ has joined #openstack-horizon | 03:41 | |
*** ratailor_ has quit IRC | 03:42 | |
*** zhurong has quit IRC | 03:42 | |
*** ratailor has quit IRC | 03:45 | |
*** yohoffman has quit IRC | 04:06 | |
*** udesale has joined #openstack-horizon | 04:21 | |
*** ratailor has joined #openstack-horizon | 04:24 | |
*** yohoffman has joined #openstack-horizon | 04:39 | |
*** masco has joined #openstack-horizon | 05:14 | |
*** ratailor_ has joined #openstack-horizon | 05:14 | |
*** ratailor has quit IRC | 05:18 | |
*** ratailor_ has quit IRC | 05:31 | |
*** ratailor has joined #openstack-horizon | 05:31 | |
*** yingwei has quit IRC | 05:34 | |
*** yingwei has joined #openstack-horizon | 05:38 | |
*** yingjun has quit IRC | 05:40 | |
*** elajkat has joined #openstack-horizon | 05:55 | |
*** tjones has quit IRC | 06:09 | |
*** zhurong has joined #openstack-horizon | 06:13 | |
*** amotoki has quit IRC | 06:19 | |
*** amotoki has joined #openstack-horizon | 06:20 | |
*** shuyingya has joined #openstack-horizon | 06:36 | |
*** mine0901 has quit IRC | 06:37 | |
*** jprovazn has joined #openstack-horizon | 06:40 | |
*** pcaruana has joined #openstack-horizon | 06:44 | |
*** ratailor has quit IRC | 06:45 | |
robcresswell | jgravel, david-lyle: Its a slight exaggeration to say I understood the issue. I confirmed it could happen, and spoke with the security guys, which as you can see led to it being classed as an impractical security bug. | 06:47 |
---|---|---|
robcresswell | jgravel, david-lyle: my thinking was that someone could do something like link to a workflow, and have the hyperlink afterward link to a mocked Horizon login page, as if the token had expired while submitting the workflow. So you could potentially steal credentials that way, I think. | 06:49 |
*** mine0901 has joined #openstack-horizon | 06:59 | |
*** zhurong has quit IRC | 07:02 | |
*** zhurong has joined #openstack-horizon | 07:06 | |
*** tesseract has joined #openstack-horizon | 07:09 | |
*** MasterOfBugs has joined #openstack-horizon | 07:20 | |
*** jpich has joined #openstack-horizon | 07:36 | |
*** zhurong has quit IRC | 07:37 | |
openstackgerrit | Galyna Zholtkevych proposed openstack/horizon master: Raise appropriate error if failed to upload image https://review.openstack.org/457992 | 07:45 |
*** VAhl has quit IRC | 07:58 | |
*** itxaka has joined #openstack-horizon | 07:59 | |
*** zhurong has joined #openstack-horizon | 08:20 | |
*** amotoki has quit IRC | 08:22 | |
*** amotoki has joined #openstack-horizon | 08:32 | |
*** makowals_ has quit IRC | 08:39 | |
*** makowals has joined #openstack-horizon | 08:52 | |
*** makowals has quit IRC | 09:04 | |
*** ratailor has joined #openstack-horizon | 09:18 | |
*** yohoffman has quit IRC | 09:19 | |
*** amotoki has quit IRC | 09:21 | |
*** ratailor has quit IRC | 09:22 | |
*** ratailor has joined #openstack-horizon | 09:22 | |
*** amotoki has joined #openstack-horizon | 09:22 | |
*** amotoki has quit IRC | 09:23 | |
*** amotoki has joined #openstack-horizon | 09:41 | |
*** ThunderEmperor has joined #openstack-horizon | 09:46 | |
ThunderEmperor | Hello Team | 09:46 |
ThunderEmperor | I have a quick question ... we have enabled | 09:46 |
ThunderEmperor | Multiple Regions on Horizon | 09:47 |
ThunderEmperor | on one of them | 09:47 |
ThunderEmperor | the Create network is missing | 09:47 |
ThunderEmperor | and in the other it is working | 09:47 |
ThunderEmperor | any ideas | 09:47 |
ThunderEmperor | This is "create network button on the Horizon portal | 09:48 |
robcresswell | ThunderEmperor: I think the only reason create net wouldnt show up is because of policy :/ | 09:54 |
ThunderEmperor | but the policy is the same | 09:55 |
ThunderEmperor | its the same horizon install | 09:55 |
ThunderEmperor | shared keystone and horizon | 09:55 |
robcresswell | ThunderEmperor: I dont know much about how regions affect policy, but doesnt that change the context of the policy? | 09:56 |
ThunderEmperor | so, this means the horizon is making the API calls | 09:56 |
robcresswell | ThunderEmperor: No, there is no policy API | 09:56 |
*** tosky has joined #openstack-horizon | 10:01 | |
ThunderEmperor | @robcresswell ... Horizon is installed in region1 | 10:01 |
ThunderEmperor | and the "create network" is not being shown up for region 2 | 10:01 |
robcresswell | ThunderEmperor: Yes, I understand, and I'm sayign that I think the only control in Horizon that shows/hides that action is a policy check | 10:03 |
robcresswell | I don't know enough about multi regions and policy to know how that interacts | 10:03 |
robcresswell | Specifically, it looks at this rule: https://github.com/openstack/horizon/blob/master/openstack_dashboard/conf/neutron_policy.json#L40 | 10:04 |
robcresswell | If that's been customised, it might be causing an issue. | 10:04 |
*** mvk has quit IRC | 10:04 | |
robcresswell | Alternatively, https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/project/networks/tables.py#L93 could be failing I suppose, and not returning True, though I'd expect a more obvious error | 10:05 |
*** zul has joined #openstack-horizon | 10:09 | |
*** sharatss has joined #openstack-horizon | 10:12 | |
sharatss | robcresswell, hi | 10:12 |
robcresswell | o/ | 10:12 |
sharatss | i need sonme help from you regarding mistral dashboard | 10:13 |
sharatss | robcresswell, ^^ | 10:13 |
robcresswell | sharatss: Sure, fire away | 10:13 |
sharatss | robcresswell, https://blueprints.launchpad.net/mistral/+spec/mistral-dashboard-search-across-pages | 10:14 |
sharatss | robcresswell, I think horizon uses magic search which serves what is asked in that BP | 10:15 |
sharatss | robcresswell, how can we use magic search in mistral? | 10:15 |
robcresswell | sharatss: There's python style server side filtering across a lot of the Horizon panels. Most of Identity dashboard, for example | 10:16 |
ThunderEmperor | I even tried disabling the rule | 10:17 |
ThunderEmperor | and changing it | 10:17 |
ThunderEmperor | but nothing seems to work | 10:17 |
ThunderEmperor | very curious | 10:17 |
robcresswell | ThunderEmperor: Have you tried replacing that entire function with just "return True" ? | 10:18 |
robcresswell | sharatss: See https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/identity/projects/tables.py#L200 and https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/identity/projects/tables.py#L264 | 10:18 |
sharatss | robcresswell, oh.. i see. I will look into it. | 10:19 |
sharatss | robcresswell, i will trouble you again if I have any queries | 10:19 |
ThunderEmperor | @robcresswell | 10:19 |
robcresswell | sharatss: Sure :) | 10:19 |
ThunderEmperor | that works | 10:19 |
ThunderEmperor | :-) | 10:20 |
ThunderEmperor | but I dont understand what ... | 10:20 |
ThunderEmperor | why this is behaving like this | 10:20 |
robcresswell | ThunderEmperor: There you go then. One thing that might be happening is that the usages code is failing and being silenced or something | 10:20 |
*** zhurong has quit IRC | 10:20 | |
robcresswell | if you commented out the policy line then it must be inside usages I guess. | 10:20 |
*** zhurong has joined #openstack-horizon | 10:28 | |
*** amotoki has quit IRC | 10:28 | |
*** yohoffman has joined #openstack-horizon | 10:30 | |
*** mvk has joined #openstack-horizon | 10:34 | |
*** jprovazn has left #openstack-horizon | 10:43 | |
*** MasterOfBugs has quit IRC | 11:06 | |
*** udesale has quit IRC | 11:06 | |
*** dave-mccowan has joined #openstack-horizon | 11:09 | |
*** makowals has joined #openstack-horizon | 11:15 | |
*** ThunderEmperor has quit IRC | 11:16 | |
sharatss | hi robcresswell | 11:41 |
sharatss | i changed the code like this https://review.openstack.org/#/c/460513/1/mistraldashboard/actions/tables.py but the search is not working | 11:42 |
sharatss | robcresswell, can u pls tell me where i have gone wrong? | 11:42 |
*** amotoki has joined #openstack-horizon | 11:45 | |
robcresswell | sharatss: See https://github.com/openstack/horizon/commit/bc1fb4910b1d500ee9e5a2d9045d8238073373f7 for the relevant full commit in Identity | 11:47 |
sharatss | thanks robcresswell | 11:50 |
*** shuyingya has quit IRC | 11:55 | |
*** shuyingya has joined #openstack-horizon | 11:55 | |
*** amotoki has quit IRC | 11:58 | |
*** amotoki has joined #openstack-horizon | 12:01 | |
*** ratailor_ has joined #openstack-horizon | 12:06 | |
*** shuyingy_ has joined #openstack-horizon | 12:08 | |
*** ratailor has quit IRC | 12:09 | |
*** shuyingya has quit IRC | 12:11 | |
*** amotoki has quit IRC | 12:19 | |
*** ducttape_ has joined #openstack-horizon | 12:21 | |
*** zhurong has quit IRC | 12:25 | |
*** amotoki has joined #openstack-horizon | 12:25 | |
*** ratailor_ has quit IRC | 12:30 | |
*** amotoki has quit IRC | 12:34 | |
*** shuyingy_ has quit IRC | 12:35 | |
*** aortega has joined #openstack-horizon | 12:42 | |
*** amotoki has joined #openstack-horizon | 12:55 | |
*** shuyingya has joined #openstack-horizon | 12:58 | |
*** zhurong has joined #openstack-horizon | 12:58 | |
*** ducttape_ has quit IRC | 12:59 | |
*** masco has quit IRC | 13:09 | |
*** yingwei has quit IRC | 13:11 | |
*** wolverineav has joined #openstack-horizon | 13:14 | |
*** catintheroof has joined #openstack-horizon | 13:17 | |
openstackgerrit | Lajos Katona proposed openstack/horizon master: New readonly panel for trunks https://review.openstack.org/449217 | 13:18 |
*** lblanchard has joined #openstack-horizon | 13:30 | |
*** lblanchard has quit IRC | 13:31 | |
openstackgerrit | Akihiro Motoki proposed openstack/horizon master: Use publicURL as default of OPENSTACK_ENDPOINT_TYPE consistently https://review.openstack.org/460551 | 13:31 |
*** lblanchard has joined #openstack-horizon | 13:33 | |
elajkat | Amotoki: I have the patch for trunk panel (https://review.openstack.org/452725), question: do you have any suggestion/example for filtering by tenant? | 13:33 |
elajkat | I am even not sure where to do that: server or angular side? | 13:33 |
amotoki | elajkat: what do you mean by 'filtering by tenant'? are you talking about the neutron behavior that all resources are returned if admin role is used? | 13:35 |
*** tjones has joined #openstack-horizon | 13:35 | |
amotoki | elajkat: In my understanding the server side should be responsible to return filtered data and the angular side should focus on "presentation". | 13:37 |
amotoki | elajkat: it is my view but I am a python developer (honestly not a JS developer) and tend to depend on server side... | 13:38 |
elajkat | ok | 13:48 |
elajkat | amotoki: Thanks, than I check the server side | 13:49 |
elajkat | amotoki: now the panel will display every trunk for every tenant anyway | 13:49 |
*** elajkat has quit IRC | 13:49 | |
amotoki | elajkat: In the design, "project" dashboard should focus on displaying resources which belong to a target tenant (project) | 13:51 |
*** ducttape_ has joined #openstack-horizon | 14:06 | |
*** ratailor has joined #openstack-horizon | 14:11 | |
*** ducttape_ has quit IRC | 14:13 | |
*** ducttape_ has joined #openstack-horizon | 14:14 | |
*** yingjun has joined #openstack-horizon | 14:20 | |
*** yingwei has joined #openstack-horizon | 14:24 | |
*** shuyingy_ has joined #openstack-horizon | 14:24 | |
*** shuyingya has quit IRC | 14:24 | |
*** ducttape_ has quit IRC | 14:28 | |
*** ducttape_ has joined #openstack-horizon | 14:29 | |
*** ratailor has quit IRC | 14:29 | |
frickler | before I start another funny "is horizon dead"-thread, pinging once more for core reviews on https://review.openstack.org/444091 to fix https://launchpad.net/bugs/1671693 , this is production affecting for us | 14:39 |
openstack | Launchpad bug 1671693 in OpenStack Dashboard (Horizon) "Rebuild instance panel does not show project images when using Glance V2" [Undecided,In progress] - Assigned to Dr. Jens Rosenboom (j-rosenboom-j) | 14:39 |
*** zhurong has quit IRC | 14:39 | |
*** ducttape_ has quit IRC | 14:40 | |
*** darrenc has quit IRC | 14:43 | |
*** lblanchard has quit IRC | 14:44 | |
*** lblanchard has joined #openstack-horizon | 14:44 | |
*** lblanchard has quit IRC | 14:44 | |
*** lblanchard has joined #openstack-horizon | 14:45 | |
*** jtriley has joined #openstack-horizon | 14:54 | |
amotoki | frickler: I am not sure why horizon is dead just only because of the coverage of well glance bug coverage. | 14:54 |
amotoki | frickler: frankly speaking, we tend to say we are suffering lack of support of individual projects. Every project makes changes they believe it is, but horizon team does not have enough resources to track all projects without supports from back-end projects | 14:56 |
amotoki | frickler: I think it is a problem on collaboration rather than horizon itself. | 14:57 |
amotoki | frickler: but i have no word if you say this is the fact "horizon is dead". | 14:58 |
amotoki | frickler: we agree that horizon glance v2 support is enough | 14:59 |
*** ducttape_ has joined #openstack-horizon | 15:00 | |
*** pcaruana has quit IRC | 15:05 | |
*** yingjun has quit IRC | 15:10 | |
*** sharatss has quit IRC | 15:13 | |
*** yingjun has joined #openstack-horizon | 15:14 | |
*** yingjun has quit IRC | 15:14 | |
frickler | amotoki: please do not be offended, I was just joking in relation to the current "is cinder dead" thread on the dev-ml. and I did ask for review of that patch a couple of times here already without success | 15:16 |
*** zigo has quit IRC | 15:17 | |
*** itxaka has quit IRC | 15:17 | |
*** ying_zuo has quit IRC | 15:19 | |
amotoki | frickler: sorry for that if you failed a couple of times. let me check it though it is not my familiar area | 15:21 |
amotoki | frickler: anyway thanks for raising it. we don't have so many active members and we are sometimes not be aware of some :( | 15:22 |
*** shuyingy_ has quit IRC | 15:22 | |
frickler | amotoki: I fully understand the lack of resources, if someone would just tell me that the patch is on their to-be-reviewed list at position 1023 and will be handled in a couple of weeks, that would be an acceptable answer, too. if there is a better way to get that kind of feedback instead of mentioning patches here, I'm happy to learn | 15:27 |
amotoki | frickler: yeah, that is very difficult problem. | 15:32 |
amotoki | frickler: I usually use a custom gerrit dashboard to highlight reviews with no feedback but if there is some reviews it will be out of the list.... | 15:32 |
amotoki | this is what I used https://review.openstack.org/#/dashboard/?foreach=%28project%3Aopenstack%2Fhorizon+OR+project%3Aopenstack%2Fdjango_openstack_auth%29+status%3Aopen+NOT+label%3ACode%252DReview%3C%3D%252D2+branch%3Amaster&title=Horizon+Review+Dashboard&My+Patches=owner%3Aself&Starred+Reviews=is%3Astarred&Your+are+a+reviewer%252c+but+haven%27t+voted+in+the+current+revision=reviewer%3Aself+NOT+label%3AWorkflow%3C% | 15:32 |
amotoki | 3D%252D1+label%3AVerified%3E%3D1%252cjenkins+NOT+label%3ACode%252DReview%3E%3D%252D2%252cself&Needs+Approval=NOT+label%3AWorkflow%3E%3D1+NOT+label%3AWorkflow%3C%3D%252D1+label%3AVerified%3E%3D1%252cjenkins+NOT+owner%3Aself+label%3ACode%252DReview%3E%3D2+NOT+label%3ACode%252DReview%252D1+NOT+label%3ACode%252DReview%3C%3D2%252cself&Not+Reviewed+by+Me=NOT+label%3ACode%252DReview%3C%3D2%252cself+limit%3A50&Needs+Reve | 15:32 |
amotoki | rify=label%3AVerified%3C%3D%252D1%252cjenkins+branch%3Amaster+NOT+label%3ACode%252DReview%3C%3D%252D1+NOT+label%3AWorkflow%3C%3D%252D1&5+Days+Without+Feedback=NOT+label%3AWorkflow%3E%3D1+NOT+label%3AWorkflow%3C%3D%252D1+label%3AVerified%3E%3D1%252cjenkins+NOT+owner%3Aself+NOT+label%3ACode%252DReview%3C%3D2+age%3A5d&No+Negative+Feedback=NOT+label%3AWorkflow%3E%3D1+NOT+label%3AWorkflow%3C%3D%252D1+label%3AVerified% | 15:32 |
amotoki | 3E%3D1%252cjenkins+NOT+owner%3Aself+NOT+label%3ACode%252DReview%3C%3D%252D1+NOT+label%3ACode%252DReview%3E%3D2+limit%3A50&With+Negative+Feedback=NOT+label%3AWorkflow%3C%3D%252D1+NOT+label%3AVerified%3C%3D%252D1%252cjenkins+NOT+owner%3Aself+label%3ACode%252DReview%252D1+limit%3A20&Work+In+Progress=NOT+label%3AWorkflow%3E%3D1+NOT+owner%3Aself+label%3AWorkflow%3C%3D%252D1 | 15:32 |
amotoki | woops......... | 15:32 |
amotoki | longer than I expected | 15:32 |
robcresswell | amotoki: paste.openstack.org :p | 15:33 |
amotoki | robcresswell: usually use it, but..... | 15:33 |
amotoki | hehe | 15:33 |
robcresswell | haha, I know :) | 15:33 |
*** yingwei has quit IRC | 15:48 | |
*** makowals has quit IRC | 15:50 | |
*** weezS has joined #openstack-horizon | 16:04 | |
*** makowals has joined #openstack-horizon | 16:06 | |
*** chlong_ has joined #openstack-horizon | 16:08 | |
*** chlong_ has quit IRC | 16:14 | |
*** makowals has quit IRC | 16:14 | |
*** makowals has joined #openstack-horizon | 16:15 | |
*** tonygunk has quit IRC | 16:17 | |
*** makowals has quit IRC | 16:17 | |
jgravel | robcresswell, thanks for chiming in on https://review.openstack.org/#/c/373540 | 16:21 |
robcresswell | jgravel: Sure. It seems valid to me, tbh | 16:22 |
robcresswell | depends if the risk there outweighs the use case david-lyle raised | 16:22 |
*** jtriley has quit IRC | 16:23 | |
jgravel | yeah, I'm not much of a security person myself so I don't have an opinion one way or other | 16:23 |
*** itxaka has joined #openstack-horizon | 16:24 | |
*** jpich has quit IRC | 16:30 | |
david-lyle | where is next populated exactly? | 16:30 |
david-lyle | we very rarely use the HTTP_REFERER | 16:31 |
david-lyle | it's passed as a parameter on the URL | 16:31 |
robcresswell | david-lyle: Yeah, I explained my thinking in the earlier comment, if you saw it | 16:32 |
robcresswell | I dont know how much of a realistic risk that is, though | 16:32 |
david-lyle | but at that point you're on a bogus page that linked to a bogus login page | 16:32 |
david-lyle | what is this going to correct there? | 16:32 |
* david-lyle promises he's not just trying to be difficult | 16:32 | |
robcresswell | Well, no, you're on a real page that redirects to a bogus login | 16:33 |
david-lyle | but to populate next, you had to be on a non-horizon page, no? | 16:33 |
robcresswell | Like if I send you to intel-dashboard.com?phishing-here | 16:33 |
robcresswell | Ah, yes, they would have had to copy a link from a non-horizon page | 16:33 |
robcresswell | which would send them to a real horizon page, and then somewhere else | 16:34 |
robcresswell | I see what you mean | 16:34 |
david-lyle | I'm not sure that's horizon's job to catch | 16:34 |
robcresswell | yeah | 16:34 |
robcresswell | I don't have any strong opinion either way about whether we fix it | 16:35 |
robcresswell | if there's a valid reason not to change the behaviour though, we should leave it | 16:35 |
robcresswell | Like you suggestion about use ase | 16:35 |
robcresswell | case* | 16:35 |
david-lyle | but if I had a super-set UI that included horizon, I may want to choose to manage my openstack cloud, obtain a token, link to a horizon using launch instance, and then have it return back to the super-set UI | 16:35 |
robcresswell | right | 16:36 |
david-lyle | but direct access to a workflow may not be practical either | 16:36 |
david-lyle | as you would need the session set up properly | 16:36 |
david-lyle | either way I guess | 16:36 |
david-lyle | I don't feel strongly, but I think the "bug" is a bit of a stretch | 16:37 |
amotoki | I see a bit different point. When reading the bug I thought "why do we need to provide a support of 'next' only in the 'workflow'?" I am not sure other django mechanism provides such mechanism | 16:37 |
david-lyle | although, I may change the code to have you launch an instance and redirect to some sort of asset registration page that is outside horizon, shrug | 16:38 |
robcresswell | amotoki: Because we launch workflows from multiple locations | 16:38 |
david-lyle | right next, is the page to return to | 16:38 |
robcresswell | yup | 16:38 |
amotoki | robcresswell: is it specific to workflow? | 16:38 |
david-lyle | once the workflow closes | 16:38 |
david-lyle | we use it for switching regions and projects as well | 16:38 |
david-lyle | and login | 16:39 |
robcresswell | and on logout? | 16:39 |
david-lyle | for that matter | 16:39 |
robcresswell | yeah ^ | 16:39 |
amotoki | ah... i see | 16:39 |
david-lyle | but I have to manipulate the URL or the code to change what next is | 16:40 |
robcresswell | right | 16:40 |
david-lyle | in the first, there is another security hole, and in the second it was intentional | 16:40 |
robcresswell | its either lazy copy pasting or malicious admins that can cause it. I think the malicious admin case is pretty void, because you could do much worse than that if you're trying to cause damage in that scenario | 16:41 |
robcresswell | So its really down to "is there a significant security threat from people copy pasting stackoverflow URLs into Horizon" | 16:42 |
robcresswell | assuming the url is right | 16:42 |
robcresswell | I think? | 16:42 |
david-lyle | that would require knowledge of the name of the horizon server | 16:42 |
robcresswell | yep | 16:43 |
*** MasterOfBugs has joined #openstack-horizon | 17:05 | |
jgravel | david-lyle, robcresswell, amotoki: Thanks for the discussion. | 17:06 |
robcresswell | Sorry, I keep getting dragged into things | 17:06 |
robcresswell | I would vote for not altering the current behaviour | 17:06 |
david-lyle | I won't block this if people think it's actually useful. I'm just not sure I see the usefulness personally | 17:06 |
*** harlowja has quit IRC | 17:08 | |
jgravel | I agree with david-lyle's point about the use case of a super-set UI. | 17:09 |
*** tosky has quit IRC | 17:09 | |
jgravel | I'm ok with not altering the current behavior. | 17:10 |
*** weezS has quit IRC | 17:13 | |
*** weezS has joined #openstack-horizon | 17:18 | |
*** jeremy_moffitt has quit IRC | 17:30 | |
*** jeremy_moffitt has joined #openstack-horizon | 17:31 | |
*** amotoki has quit IRC | 17:32 | |
*** weezS has quit IRC | 17:37 | |
*** gyee has joined #openstack-horizon | 17:43 | |
openstackgerrit | Valeriy Ponomaryov proposed openstack/manila-ui master: Fix manila quota operations https://review.openstack.org/460698 | 17:49 |
*** harlowja has joined #openstack-horizon | 17:51 | |
*** mvk has quit IRC | 17:53 | |
openstackgerrit | Valeriy Ponomaryov proposed openstack/manila-ui master: Fix manila quota operations https://review.openstack.org/460698 | 17:55 |
*** erlon has joined #openstack-horizon | 17:57 | |
openstackgerrit | Ying Zuo proposed openstack/horizon master: Set minimum volume size based on the flavor selected https://review.openstack.org/450489 | 17:58 |
*** tosky has joined #openstack-horizon | 17:59 | |
openstackgerrit | Valeriy Ponomaryov proposed openstack/manila-ui master: Fix share creation from snapshot https://review.openstack.org/460248 | 18:03 |
*** Matias has joined #openstack-horizon | 18:05 | |
openstackgerrit | Valeriy Ponomaryov proposed openstack/manila-ui master: Fix manila quota operations https://review.openstack.org/460698 | 18:05 |
*** ying_zuo has joined #openstack-horizon | 18:24 | |
*** john51_ has quit IRC | 18:34 | |
*** john51 has joined #openstack-horizon | 18:34 | |
*** fnordahl_ has joined #openstack-horizon | 18:38 | |
*** fnordahl has quit IRC | 18:38 | |
*** ethfci has quit IRC | 18:38 | |
*** ethfci has joined #openstack-horizon | 18:39 | |
openstackgerrit | Merged openstack/manila-ui master: Fix share creation from snapshot https://review.openstack.org/460248 | 18:46 |
*** openstackgerrit has quit IRC | 18:48 | |
*** ducttape_ has quit IRC | 18:54 | |
*** itxaka has quit IRC | 19:00 | |
*** ducttape_ has joined #openstack-horizon | 19:07 | |
*** ducttape_ has quit IRC | 19:07 | |
*** mvk has joined #openstack-horizon | 19:08 | |
*** ducttape_ has joined #openstack-horizon | 19:13 | |
*** lblanchard has quit IRC | 19:22 | |
*** nandal has joined #openstack-horizon | 19:38 | |
*** nandal has quit IRC | 19:38 | |
*** ducttape_ has quit IRC | 19:53 | |
*** ducttape_ has joined #openstack-horizon | 19:56 | |
*** ducttape_ has quit IRC | 19:57 | |
*** ducttape_ has joined #openstack-horizon | 20:06 | |
*** makowals has joined #openstack-horizon | 20:11 | |
*** mine0901 has quit IRC | 20:27 | |
*** ducttape_ has quit IRC | 20:29 | |
*** makowals has quit IRC | 20:33 | |
*** aortega has quit IRC | 20:38 | |
*** ducttape_ has joined #openstack-horizon | 20:43 | |
*** ducttape_ has quit IRC | 20:43 | |
*** ducttape_ has joined #openstack-horizon | 21:19 | |
*** aortega has joined #openstack-horizon | 21:20 | |
*** ducttape_ has quit IRC | 21:25 | |
*** zigo has joined #openstack-horizon | 21:32 | |
*** ducttape_ has joined #openstack-horizon | 21:36 | |
*** ducttape_ has quit IRC | 21:40 | |
*** catintheroof has quit IRC | 22:00 | |
*** jose-phillips has joined #openstack-horizon | 22:01 | |
*** ducttape_ has joined #openstack-horizon | 22:10 | |
*** erlon has quit IRC | 22:13 | |
*** abramley has quit IRC | 22:13 | |
*** harlowja has quit IRC | 22:14 | |
*** mnaser has quit IRC | 22:16 | |
*** nikhil has quit IRC | 22:17 | |
*** Alex_Oughton has quit IRC | 22:17 | |
*** tlbr has quit IRC | 22:17 | |
*** AlexOughton has joined #openstack-horizon | 22:18 | |
*** tlbr has joined #openstack-horizon | 22:20 | |
*** mnaser has joined #openstack-horizon | 22:21 | |
*** nikhil has joined #openstack-horizon | 22:26 | |
*** abramley has joined #openstack-horizon | 22:36 | |
*** openstackgerrit has joined #openstack-horizon | 22:39 | |
openstackgerrit | Merged openstack/horizon master: Ensure log messages are not translated https://review.openstack.org/455635 | 22:39 |
openstackgerrit | Merged openstack/horizon master: usage: Ensure to count resources of a given project https://review.openstack.org/431793 | 22:43 |
*** ducttape_ has quit IRC | 22:43 | |
*** ducttape_ has joined #openstack-horizon | 22:45 | |
*** ducttape_ has quit IRC | 22:45 | |
*** ducttape_ has joined #openstack-horizon | 22:50 | |
*** adriant_ has joined #openstack-horizon | 23:07 | |
*** wolverineav has quit IRC | 23:19 | |
*** wolverineav has joined #openstack-horizon | 23:19 | |
*** tesseract has quit IRC | 23:20 | |
*** harlowja has joined #openstack-horizon | 23:23 | |
*** wolverineav has quit IRC | 23:24 | |
*** tosky has quit IRC | 23:46 | |
*** ducttape_ has quit IRC | 23:51 | |
*** ducttape_ has joined #openstack-horizon | 23:52 | |
*** ducttape_ has quit IRC | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!