Tuesday, 2016-06-14

*** lyrrad has quit IRC00:25
*** Sashimi has quit IRC00:26
*** openstackgerrit has quit IRC03:11
*** openstackgerrit has joined #swift303:12
openstackgerritKota Tsuyuzaki proposed openstack/swift3: Deny all access to controller instance method  https://review.openstack.org/32926504:52
kota_timburke: here?04:53
kota_If you have a time, I hope you could take a time to review https://review.openstack.org/329265 as soon as possible.04:54
timburkehi kota_! yes, but probably not for very long04:54
kota_I don't think it's a significant security issue but04:54
kota_it could be a risk of any verb attack for all s3 controller requests.04:54
timburkeah, good call. indeed. will make sure it's reviewed quickly04:55
kota_timburke: thanks04:55
kota_the reason it exists is why current swift3 checks only existence of each verbs (like GET, PUT) and nothing denied if *it exists*04:56
kota_I noticed that when reading the conversation between jilichli and notmyname for encryption reviews in this morning :)04:57
kota_decrypter seems to have same issue and I'm feeling swift3 too!04:57
timburkeyeah, i saw that convo too. i might need to audit some swiftstack middleware now...05:05
kota_ok, thanks.05:10
kota_wooo, handling AttributeError seems worse? :P Since continuing to read the rest of conversations....05:20
*** Sashimi has joined #swift306:47
*** openstackgerrit has quit IRC06:48
*** openstackgerrit has joined #swift306:49
*** Sashimi has quit IRC07:07
*** acoles_ is now known as acoles08:58
*** Shashikant86 has joined #swift308:59
*** Shashikant86 has quit IRC09:24
*** Shashikant86 has joined #swift309:32
*** Shashikant86 has quit IRC10:42
*** Shashikant86 has joined #swift311:05
*** Shashikant86 has quit IRC11:35
*** Shashikant86 has joined #swift311:55
*** Shashikant86 has quit IRC13:32
*** Sashimi has joined #swift313:32
*** Shashikant86 has joined #swift313:34
*** Sashimi has quit IRC13:45
*** Sashimi has joined #swift313:51
*** Shashikant86 has quit IRC13:54
*** bill_az has joined #swift314:22
*** Shashikant86 has joined #swift314:25
*** bill_az has quit IRC14:54
*** Shashikant86 has quit IRC15:58
*** lyrrad has joined #swift316:22
*** acoles is now known as acoles_18:10
*** Sashimi has quit IRC19:13
*** openstack has joined #swift322:28
*** Sashimi has joined #swift322:44

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!