1. 22 May, 2015 4 commits
  2. 30 Apr, 2015 2 commits
  3. 21 Apr, 2015 1 commit
  4. 01 Apr, 2015 1 commit
    • Leigh B Stoller's avatar
      Tighten up permissions granted to geni users coming from the GPO Portal. · 105c42e1
      Leigh B Stoller authored
      We now ask the portal for a the user's project membership list, and if the
      user is not a member of any (unexpired) projects, we do not allow them to
      create experiments (or much of anything else) in the Cloud Portal. I did
      this by setting the local holding project trust to "user" and setting the
      webonly bit in the users table. The user can use the picker to see public
      profiles, but the create button tells them no dice, go join a project at
      the GPO portal.
      
      We make the project check each time the user logs in via the trusted
      signer.
      105c42e1
  5. 19 Mar, 2015 1 commit
  6. 10 Mar, 2015 1 commit
  7. 09 Mar, 2015 2 commits
  8. 05 Mar, 2015 2 commits
  9. 13 Feb, 2015 1 commit
  10. 04 Feb, 2015 1 commit
    • Leigh B Stoller's avatar
      Reduce the RPC timeout to 60 seconds in the sliverstatus loop, and · 31f8c5f4
      Leigh B Stoller authored
      say something more informative them "read timeout" if we lose contact
      with the backend cluster.
      
      I still need to figure out what to do when this happens, At the moment we
      set the status of the new instance to failed, even though it can't be
      terminated until the network partition clears up.
      31f8c5f4
  11. 29 Jan, 2015 1 commit
  12. 27 Jan, 2015 2 commits
    • Leigh B Stoller's avatar
      Two co-mingled sets of changes: · 85cb063b
      Leigh B Stoller authored
      1) Implement the latest dataset read/write access settings from frontend to
         backend. Also updates for simultaneous read-only usage.
      
      2) New configure options: PROTOGENI_LOCALUSER and PROTOGENI_GENIWEBLOGIN.
      
         The first changes the way that projects and users are treated at the
         CM. When set, we create real accounts (marked as nonlocal) for users and
         also create real projects (also marked as nonlocal). Users are added to
         those projects according to their credentials. The underlying experiment
         is thus owned by the user and in the project, although all the work is
         still done by the geniuser pseudo user. The advantage of this approach
         is that we can use standard emulab access checks to control access to
         objects like datasets. Maybe images too at some point.
      
         NOTE: Users are not removed from projects once they are added; we are
         going to need to deal with this, perhaps by adding an expiration stamp
         to the groups_membership tables, and using the credential expiration to
         mark it.
      
         The second new configure option turns on the web login via the geni
         trusted signer. So, if I create a sliver on a backend cluster when both
         options are set, I can use the trusted signer to log into my newly
         created account on the cluster, and see it (via the emulab classic web
         interface).
      
         All this is in flux, might end up being a bogus approach in the end.
      85cb063b
    • Leigh B Stoller's avatar
      Add ssh key management to Actions menu, do not delete keys in · 7a07142a
      Leigh B Stoller authored
      create_instance, now that user can manage multiple keys.
      7a07142a
  13. 16 Jan, 2015 1 commit
  14. 03 Jan, 2015 1 commit
  15. 15 Dec, 2014 1 commit
  16. 04 Dec, 2014 1 commit
  17. 03 Dec, 2014 3 commits
  18. 12 Nov, 2014 1 commit
  19. 29 Oct, 2014 1 commit
  20. 28 Oct, 2014 1 commit
  21. 27 Oct, 2014 1 commit
  22. 25 Oct, 2014 1 commit
  23. 08 Oct, 2014 1 commit
  24. 24 Sep, 2014 2 commits
  25. 18 Sep, 2014 1 commit
  26. 15 Sep, 2014 1 commit
    • Leigh B Stoller's avatar
      Change to ssh key handling for registered APT/Cloud users; show the ssh key · 1822694e
      Leigh B Stoller authored
      box, but as a collapsible. Warn user if they do not have a key (provided on
      signup page) that they are restricted to browser shell. Whenever user
      provides a key, replace in the database (if its changed). This keeps the
      user out of the Emulab interface to edit their ssh keys. Might have to
      revisit this if APT/Cloud users need/want more then the one key.
      1822694e
  27. 09 Sep, 2014 1 commit
  28. 08 Sep, 2014 1 commit
  29. 03 Sep, 2014 1 commit
  30. 02 Sep, 2014 1 commit