1. 15 Jun, 2015 1 commit
  2. 10 Jun, 2015 3 commits
  3. 09 Jun, 2015 1 commit
  4. 22 May, 2015 4 commits
  5. 30 Apr, 2015 2 commits
  6. 21 Apr, 2015 1 commit
  7. 01 Apr, 2015 1 commit
    • Leigh B Stoller's avatar
      Tighten up permissions granted to geni users coming from the GPO Portal. · 105c42e1
      Leigh B Stoller authored
      We now ask the portal for a the user's project membership list, and if the
      user is not a member of any (unexpired) projects, we do not allow them to
      create experiments (or much of anything else) in the Cloud Portal. I did
      this by setting the local holding project trust to "user" and setting the
      webonly bit in the users table. The user can use the picker to see public
      profiles, but the create button tells them no dice, go join a project at
      the GPO portal.
      We make the project check each time the user logs in via the trusted
  8. 19 Mar, 2015 1 commit
  9. 10 Mar, 2015 1 commit
  10. 09 Mar, 2015 2 commits
  11. 05 Mar, 2015 2 commits
  12. 13 Feb, 2015 1 commit
  13. 04 Feb, 2015 1 commit
    • Leigh B Stoller's avatar
      Reduce the RPC timeout to 60 seconds in the sliverstatus loop, and · 31f8c5f4
      Leigh B Stoller authored
      say something more informative them "read timeout" if we lose contact
      with the backend cluster.
      I still need to figure out what to do when this happens, At the moment we
      set the status of the new instance to failed, even though it can't be
      terminated until the network partition clears up.
  14. 29 Jan, 2015 1 commit
  15. 27 Jan, 2015 2 commits
    • Leigh B Stoller's avatar
      Two co-mingled sets of changes: · 85cb063b
      Leigh B Stoller authored
      1) Implement the latest dataset read/write access settings from frontend to
         backend. Also updates for simultaneous read-only usage.
         The first changes the way that projects and users are treated at the
         CM. When set, we create real accounts (marked as nonlocal) for users and
         also create real projects (also marked as nonlocal). Users are added to
         those projects according to their credentials. The underlying experiment
         is thus owned by the user and in the project, although all the work is
         still done by the geniuser pseudo user. The advantage of this approach
         is that we can use standard emulab access checks to control access to
         objects like datasets. Maybe images too at some point.
         NOTE: Users are not removed from projects once they are added; we are
         going to need to deal with this, perhaps by adding an expiration stamp
         to the groups_membership tables, and using the credential expiration to
         mark it.
         The second new configure option turns on the web login via the geni
         trusted signer. So, if I create a sliver on a backend cluster when both
         options are set, I can use the trusted signer to log into my newly
         created account on the cluster, and see it (via the emulab classic web
         All this is in flux, might end up being a bogus approach in the end.
    • Leigh B Stoller's avatar
      Add ssh key management to Actions menu, do not delete keys in · 7a07142a
      Leigh B Stoller authored
      create_instance, now that user can manage multiple keys.
  16. 16 Jan, 2015 1 commit
  17. 03 Jan, 2015 1 commit
  18. 15 Dec, 2014 1 commit
  19. 04 Dec, 2014 1 commit
  20. 03 Dec, 2014 3 commits
  21. 12 Nov, 2014 1 commit
  22. 29 Oct, 2014 1 commit
  23. 28 Oct, 2014 1 commit
  24. 27 Oct, 2014 1 commit
  25. 25 Oct, 2014 1 commit
  26. 08 Oct, 2014 1 commit
  27. 24 Sep, 2014 2 commits
  28. 18 Sep, 2014 1 commit