Project

Profile

Help

Issue #8870

Unpublished content can be accessed if relative path of content is know

Added by dalley 3 months ago. Updated 22 days ago.

Status:
CLOSED - CURRENTRELEASE
Priority:
Normal
Assignee:
Category:
-
Sprint/Milestone:
Start date:
Due date:
Estimated time:
Severity:
2. Medium
Version:
Platform Release:
OS:
Triaged:
Yes
Groomed:
No
Sprint Candidate:
No
Tags:
Sprint:
Sprint 102
Quarter:

Description

It is expected for the package to be available at http://pulp3-source-centos7/pulp/content/fixture/Packages/b/bear-4.1-1.noarch.rpm

It is not expected for the package to be available at http://pulp3-source-centos7/pulp/content/fixture/bear-4.1-1.noarch.rpm (the root of the repo)

Neither primary.xml nor the directory listing show the files in the repo root, although they are that way in the original repo.

To reproduce:

pulp rpm remote create --name=fixture --url=https://fixtures.pulpproject.org/rpm-unsigned/ --policy=on_demand
pulp rpm repository create --name=fixture --remote=fixture
pulp rpm repository sync --name fixture
pulp rpm publication create --repository fixture
pulp rpm distribution create --name fixture --repository fixture --base-path=fixture

Related issues

Related to RPM Support - Issue #9071: Getting 500 error while accessing pulp/content/reponame/config.repoCLOSED - CURRENTRELEASE<a title="Actions" class="icon-only icon-actions js-contextmenu" href="#">Actions</a>
Copied to Pulp - Issue #9126: Backport 8870 "Unpublished content can be accessed if relative path of content is known" to 3.14.zCLOSED - CURRENTRELEASE<a title="Actions" class="icon-only icon-actions js-contextmenu" href="#">Actions</a>
Copied to RPM Support - Issue #9223: Unpublished content can be accessed if relative path of content is knowCLOSED - CURRENTRELEASE<a title="Actions" class="icon-only icon-actions js-contextmenu" href="#">Actions</a>

Associated revisions

Revision 27a0dc74 View on GitHub
Added by gerrod about 1 month ago

Prevent access to unpublished content from content app

fixes: #8870 https://pulp.plan.io/issues/8870 Required PR: https://github.com/pulp/pulp_file/pull/547

History

#1 Updated by dalley 3 months ago

None of the repodata files are available from the root.

#2 Updated by dkliban@redhat.com 3 months ago

  • Project changed from Pulp to RPM Support

#3 Updated by dalley 3 months ago

  • Priority changed from Normal to Low
  • Triaged changed from No to Yes

#4 Updated by dalley 2 months ago

  • Project changed from RPM Support to Pulp

#5 Updated by gerrod 2 months ago

  • Subject changed from Packages which weren't published at the repository root are available at the repository root to Unpublished content can be accessed if relative path of content is know
  • Assignee set to gerrod
  • Priority changed from Low to Normal

This problem affects all publication based plugins. Steps to reproduce

  1. Create repo: pulp file repository create --name test
  2. Create remote: pulp file remote create --name test --url https://fixtures.pulpproject/file/PULP_MANIFEST
  3. Sync repo: pulp file repository sync --name test --remote test
  4. Create distribution: pulp file distribution create --name test --base-path test --repository test
  5. Access unpublished content: http :24816/pulp/content/test/1.iso
  6. Get 404 for published metadata: http :24816/pulp/content/test/PULP_MANIFEST

#6 Updated by dalley 2 months ago

  • Status changed from NEW to ASSIGNED
  • Sprint set to Sprint 100

#7 Updated by dalley 2 months ago

  • Related to Issue #9071: Getting 500 error while accessing pulp/content/reponame/config.repo added

#8 Updated by pulpbot 2 months ago

  • Status changed from ASSIGNED to POST

#9 Updated by rchan 2 months ago

  • Sprint changed from Sprint 100 to Sprint 101

#10 Updated by dalley about 2 months ago

  • Sprint/Milestone set to 3.15.0

#11 Updated by dalley about 2 months ago

  • Copied to Issue #9126: Backport 8870 "Unpublished content can be accessed if relative path of content is known" to 3.14.z added

#12 Updated by ipanova@redhat.com about 2 months ago

  • Sprint changed from Sprint 101 to Sprint 102

#13 Updated by gerrod about 1 month ago

  • Status changed from POST to MODIFIED

#14 Updated by ipanova@redhat.com about 1 month ago

  • Copied to Issue #9223: Unpublished content can be accessed if relative path of content is know added

#15 Updated by pulpbot 22 days ago

  • Status changed from MODIFIED to CLOSED - CURRENTRELEASE

Please register to edit this issue

Also available in: Atom PDF