Uploaded image for project: 'Artifactory Binary Repository'
  1. Artifactory Binary Repository
  2. RTFACT-18447

Users are allowed to overwrite the manifest.json even if they have deploy/cache permissions only

    Details

    • Type: Bug
    • Status: Open
    • Priority: Normal
    • Resolution: Unresolved
    • Affects Version/s: 6.7.0
    • Fix Version/s: None
    • Component/s: Docker
    • Labels:

      Description

      After creating a docker registry and giving users permissions to deploy/cache only, pushing the same image twice will cause the manifest.json metadata to be changed (deployed by and last modified). This will not happen if the contents of manifest.json the user tries to push are different than what's stored in artifactory.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              rafael Rafael Cunha de Almeida
            • Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

              • Created:
                Updated: