Uploaded image for project: 'Traffic Control'
  1. Traffic Control
  2. TC-533

DS SSL key apis needs to have tenancy check in place

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.1.0
    • 2.1.0, 2.2.0
    • Traffic Ops API
    • None

    Description

      Tenancy was introduced in 2.1, however, by default it is turned off via the use_tenancy parameter but when activated it is used to limit the scope of delivery services that a user can act on.

      The following APIs needs to check tenancy to ensure users cannot act on ds's that they don't have access to.

      get("/api/$version/deliveryservices/xmlId/#xmlid/sslkeys
      post("/api/$version/deliveryservices/sslkeys/generate
      post("/api/$version/deliveryservices/sslkeys/add
      get("/api/$version/deliveryservices/xmlId/:xmlid/sslkeys/delete

      Attachments

        Activity

          People

            nirsopher Nir Sopher
            mitchell852@apache.org Jeremy Mitchell
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: