summaryrefslogtreecommitdiffstats
path: root/etc/zaqar/policy.json
diff options
context:
space:
mode:
authorSean Pryor <spryor@redhat.com>2017-06-05 15:35:25 -0400
committerSean Pryor <spryor@redhat.com>2017-06-05 15:35:25 -0400
commitab91ff350034a186fe7f1400c2ffece96efaeacf (patch)
treebb078096a7fd7f78b76028e2d037034a0e88780d /etc/zaqar/policy.json
parent8da390dc08f48fbfaf3d35c0576d65b5085a0b8c (diff)
downloadopenstack-access-policy-ab91ff350034a186fe7f1400c2ffece96efaeacf.tar.gz
openstack-access-policy-ab91ff350034a186fe7f1400c2ffece96efaeacf.tar.xz
openstack-access-policy-ab91ff350034a186fe7f1400c2ffece96efaeacf.zip
Created branch 'original' with unmodified policies
Change-Id: Ia0b0ae2786caabf70b16020bfdfe26c4b02fa0ea
Diffstat (limited to 'etc/zaqar/policy.json')
-rw-r--r--etc/zaqar/policy.json31
1 files changed, 15 insertions, 16 deletions
diff --git a/etc/zaqar/policy.json b/etc/zaqar/policy.json
index 9dff654..89d5076 100644
--- a/etc/zaqar/policy.json
+++ b/etc/zaqar/policy.json
@@ -1,34 +1,33 @@
{
- "deny_readonly": "not role:readonly",
- "context_is_admin": "role:admin and rule:deny_readonly",
+ "context_is_admin": "role:admin",
"admin_or_owner": "is_admin:True or project_id:%(project_id)s",
- "default": "rule:admin_or_owner and rule:deny_readonly",
+ "default": "rule:admin_or_owner",
"queues:get_all": "",
- "queues:create": "rule:deny_readonly",
+ "queues:create": "",
"queues:get": "",
- "queues:delete": "rule:deny_readonly",
- "queues:update": "rule:deny_readonly",
+ "queues:delete": "",
+ "queues:update": "",
"queues:stats": "",
"messages:get_all": "",
- "messages:create": "rule:deny_readonly",
+ "messages:create": "",
"messages:get": "",
- "messages:delete": "rule:deny_readonly",
- "messages:delete_all": "rule:deny_readonly",
+ "messages:delete": "",
+ "messages:delete_all": "",
"claims:get_all": "",
- "claims:create": "rule:deny_readonly",
+ "claims:create": "",
"claims:get": "",
- "claims:delete": "rule:deny_readonly",
- "claims:update": "rule:deny_readonly",
+ "claims:delete": "",
+ "claims:update": "",
"subscription:get_all": "",
- "subscription:create": "rule:deny_readonly",
+ "subscription:create": "",
"subscription:get": "",
- "subscription:delete": "rule:deny_readonly",
- "subscription:update": "rule:deny_readonly",
- "subscription:confirm": "rule:deny_readonly",
+ "subscription:delete": "",
+ "subscription:update": "",
+ "subscription:confirm": "",
"pools:get_all": "rule:context_is_admin",
"pools:create": "rule:context_is_admin",