Skip to content
This repository has been archived by the owner on Feb 29, 2024. It is now read-only.

Commit

Permalink
Merge "Update Barbican Orders policy for secure-rbac" into stable/wal…
Browse files Browse the repository at this point in the history
…laby
  • Loading branch information
Zuul authored and openstack-gerrit committed Mar 2, 2022
2 parents 10894e5 + ccb4cfb commit 09c1ce2
Showing 1 changed file with 5 additions and 2 deletions.
7 changes: 5 additions & 2 deletions environments/enable-secure-rbac.yaml
Expand Up @@ -2996,6 +2996,9 @@ parameter_defaults:
barbican-container_project_member:
key: "container_project_member"
value: "rule:member and project_id:%(target.container.project_id)s"
barbican-order_project_member:
key: "order_project_member"
value: "rule:member and project_id:%(target.order.project_id)s"
barbican-secret_acls_get:
key: "secret_acls:get"
value: "rule:secret_project_member and (rule:secret_owner or rule:secret_is_not_private_read) or rule:secret_project_admin"
Expand Down Expand Up @@ -3055,10 +3058,10 @@ parameter_defaults:
value: "rule:member"
barbican-order_get:
key: "order:get"
value: "rule:member"
value: "rule:order_project_member"
barbican-order_delete:
key: "order:delete"
value: "rule:member"
value: "rule:order_project_member"
barbican-quotas_get:
key: "quotas:get"
value: "rule:reader"
Expand Down

0 comments on commit 09c1ce2

Please sign in to comment.