Comment 7 for bug 1040626

Revision history for this message
Dolph Mathews (dolph) wrote : Re: Update user's default tenant partially succeeds without authz

I would clarify the last sentence a bit further, as: "The result is that any client that can reach the administrative API (deployed on port 35357, by default) can add any user to any tenant."

As originally stated, there are two different uses of the word "user" (the first being a user of the API, and the second being an entity in the Identity system).