[katello-devel] Oauth issue for non-admin users

Lukas Zapletal lzap at redhat.com
Fri Jul 8 13:57:00 UTC 2011


On 07/08/2011 02:08 PM, Dmitri Dolguikh wrote:
> The final goal is:
>   - if oauth is used, candlepin doesn't perform any authentication or
> access control, but rather relies on katello to do both
>   - user identity (username for now) is passed in cp-user/cp-consumer
> oauth header
>
> Devan, do you know where cp folks are in regard to #1?

Hmmm. Well if I try to register a system under regular user account 
(e.g. "bob"), Katello properly sends cp-user header but Candlepin 
replies with Bad Request 400 (user bob not found).

There is no such user ("bob") in Candlepin. Is this correct behavior?

-- 
Later,

  Lukas Zapletal | E32E400A
  RHN Satellite Engineering
  Red Hat Czech s.r.o. Brno




More information about the katello-devel mailing list