)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"change_message_id":"86d8894ba2fd1b7c291767ba36a2c2073d8cff2b","unresolved":true,"context_lines":[{"line_number":17,"context_line":"Depends-On: https://review.opendev.org/c/openstack/cinder/+/986472"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"Change-Id: I72a404d091563d2eba23f21019be797a8667b3db"},{"line_number":20,"context_line":"Signed-off-by: Ghanshyam Mann \u003cgmann@ghanshyammann.com\u003e"},{"line_number":21,"context_line":"Signed-off-by: Ghanshyam Maan \u003cgmaan.os14@gmail.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":28,"id":"84a4eeef_76f58344","line":20,"updated":"2026-06-26 14:48:20.000000000","message":"Duplicate line ;)","commit_id":"5d519fcc2467d6868cc162da5acc84226cc7ce42"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"959a2f57db013389c9711c12ea6c3777ec0166cf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"a1eca986_ced9edba","updated":"2024-08-30 07:57:32.000000000","message":"recheck test trigger","commit_id":"6a7b3b70c684a67ac842c3a8e88b0d60f76af213"},{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"a6535b5b09f1686aa7f1913673c8686e715e8007","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"f633ec9f_88eb015a","updated":"2025-01-16 09:15:40.000000000","message":"Maybe it is irrelevant or I am missing a context. But when oslo.policy 4.4.0 enables the new RBAC config options and enforce_scope, enforce_new_defaults are enabled by default for all the OpenStack services, should we remove this?\nhttps://github.com/openstack/horizon/blob/cbea7e9e882ade55cee42077b1677598c65b6b58/openstack_auth/policy.py#L38C1-L43C57\nOr do we want/need to set those variables to False anyway for some reasons?\nAnd if yes, then based on the doc we probably should do it via service configuration file.\n\nCould someone please clarify it for me? Thanks!","commit_id":"0ed8597e675cf655da6abb32f9f4d0ed56580871"},{"author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"change_message_id":"6ed793319caea7b749f1a3b9b9f8d509d7be5f43","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"d7166def_f76f0886","in_reply_to":"99d3ebb1_8d97dae8","updated":"2025-05-22 14:59:23.000000000","message":"Hmm, need additional check for this..","commit_id":"0ed8597e675cf655da6abb32f9f4d0ed56580871"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"0af64a47694747ea3df8906ca774d7f4ed8fa845","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"99d3ebb1_8d97dae8","in_reply_to":"f633ec9f_88eb015a","updated":"2025-02-18 20:21:46.000000000","message":"you are right, we need to remove those default override. I meant to do those update and test the same but was not getting the bandwidth. let me do that now","commit_id":"0ed8597e675cf655da6abb32f9f4d0ed56580871"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"8b0c6bc219c2f1038e238e0a9cfe375f2ae10011","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"542c7b5f_34372f80","updated":"2025-02-18 20:29:30.000000000","message":"WIP until testing it completed","commit_id":"c936b3696045d4665e80d214c28130a1ab9dda8a"},{"author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"change_message_id":"0a275ba89271f3ad333bf2ad62b2340f27038751","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":22,"id":"17a320a0_7a93561d","updated":"2025-08-11 23:05:03.000000000","message":"recheck (new results)","commit_id":"c4c19f58441b32f7fef508f1c9ff46beb035a175"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"e6dd72e107d533e91e03e6daea5d12db8e9a4604","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":27,"id":"5bfd43c5_08fd11aa","updated":"2025-10-27 23:47:10.000000000","message":"marking it as WIP, I also need to check the generated policy files and if old or new defaults are present?","commit_id":"60b3a2dac66e688c33f3546859238e2f1af363d4"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"cf8b99ed4d6df18789b883ffe8c9d62ae1d06a49","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":27,"id":"ebec9dbe_d73c5974","in_reply_to":"5bfd43c5_08fd11aa","updated":"2026-06-26 14:34:31.000000000","message":"default policies are sync to the new defaults so we are good on that https://github.com/openstack/horizon/tree/master/openstack_dashboard/conf/default_policies","commit_id":"60b3a2dac66e688c33f3546859238e2f1af363d4"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"194f24e6f83a7e8409dd29ef5f1de022e63d0a19","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":29,"id":"d08140ef_51782d0e","updated":"2026-07-03 13:45:44.000000000","message":"I think the ProjectsViewNonAdminTests is failing correctly here? I mean, if I manually login as a non-admin user, with this patch applied, the identity-\u003eprojects menu entry is not available for me, so no wonder there is a permission error when the test is trying to access it. Now, the question is, should that menu entry be available?","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"b4f11b968de5c9bceb498090ebd9be4f542ce06f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":29,"id":"622c4c2a_6af174a7","in_reply_to":"249da7a8_bfbf2291","updated":"2026-07-09 06:01:41.000000000","message":"If that is the desired behavior, we should either not have a policy check on the projects panel at all (the api will only list the projects the user has access to anyways), or somehow pass the user\u0027s project as the target for the security check. Realistically, is there any case where we don\u0027t want the users to have access to that panel at all?","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"557c5b3020e1c90abd27be673889f51e735156e1","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":29,"id":"e015c420_b28c4c5d","in_reply_to":"622c4c2a_6af174a7","updated":"2026-07-09 17:45:14.000000000","message":"I cannot think of that case where users should not have access to panel at all, if they do not have any access then they get empty page which is all ok.","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"2740291ac6cfd097524da9ee1094c910f91e928d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":29,"id":"f70d5763_d596c266","in_reply_to":"6ed601ba_dc5258e6","updated":"2026-07-13 17:02:03.000000000","message":"thanks, i rebased on top of that.","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a098e9897f2435d423d70ff644170c2e543ade72","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":29,"id":"d012c95d_83738996","in_reply_to":"862b2700_c09a20d9","updated":"2026-07-03 15:05:18.000000000","message":"It is strange because there is no change in those policies from old to new defaults from the project-scoped non-admin token.\n\n\n\"identity\", \"identity:list_projects\": non-admin should not be able to access it as it is admin-only.\n\n* old defaults: admin[1]\n* new defaults: admin or system|domain reader can access[2]\n\n\"identity\", \"identity:list_user_projects\": This is owner + admin means, if same user is accessing (policy checks user_id as owner[3]) then non-admin is allowed\n\n* old defaults: admin or owner [4]\n* new defaults: admin or owner or system|domain reader[5]\n\n[1] https://github.com/openstack/keystone/blob/4172e784581e71b468325c05f4e9023c0fefd9b5/keystone/common/policies/project.py#L171\n[2] https://github.com/openstack/keystone/blob/4172e784581e71b468325c05f4e9023c0fefd9b5/keystone/common/policies/project.py#L80\n[3] https://github.com/openstack/keystone/blob/4172e784581e71b468325c05f4e9023c0fefd9b5/keystone/common/policies/base.py#L17\n[4] https://github.com/openstack/keystone/blob/4172e784581e71b468325c05f4e9023c0fefd9b5/keystone/common/policies/project.py#L92\n[5] https://github.com/openstack/keystone/blob/4172e784581e71b468325c05f4e9023c0fefd9b5/keystone/common/policies/project.py#L179 \n\nI can see horizon policy defaults file also has the same: https://github.com/openstack/horizon/blob/e48473ce019c69eea261f2116bbeb161a660d3b6/openstack_dashboard/conf/default_policies/keystone.yaml#L1920-L1951\n\n\n@openstack@dopieralski.pl\n\nAs there is no change from non-admin perspective/access level. Can you please confirm if you see the same behaviour/can access the project page before applying this change?","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"b8b2c256e8917e7ed95b2e044f7ba828b75439d7","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":29,"id":"db76a0a3_9e9af90d","in_reply_to":"d012c95d_83738996","updated":"2026-07-07 07:00:16.000000000","message":"There is a change in behavior. Before the patch, I can access the identity-\u003eprojects panel as the demo user, after the patch I can\u0027t.\n\nAs far as I can tell, the \"owner\" permission here is irrelevant, because we never pass a particular project_id to the policy check when checking the panel -- so the user would need to be an admin or domain admin. No idea why it works before the patch, maybe some system token clause gets triggered?","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"79b1b26fe1710aea470ea505afa35a6fef61796d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":29,"id":"862b2700_c09a20d9","in_reply_to":"d08140ef_51782d0e","updated":"2026-07-03 13:47:17.000000000","message":"The panel uses the following policies to decide whether it should be accessible or not:\n\n    policy_rules \u003d ((\"identity\", \"identity:list_projects\"),\n                    (\"identity\", \"identity:list_user_projects\"))","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"20c16c7ba827e47ee616f392a39eae9951cb2415","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":29,"id":"249da7a8_bfbf2291","in_reply_to":"db76a0a3_9e9af90d","updated":"2026-07-08 22:16:33.000000000","message":"system token should not be the thing as demo users should not have \u0027system_scope:all\u0027 in the token. I think it used to go via domain reader? and with scoped enabled, it is fixing this issue.\n\nI am trying to understand the expected behaviour so that we can debug in the right direction. If I understand correctly, the expected behaviour is:\n- a admin user can see identity-\u003eprojects panel with all the projects listed there\n- a non-admin user will still see the  identity-\u003eprojects panel but only see the projects they belong to.","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"4c60d1a1dee6427f1b2133242fad09c4369590a1","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":29,"id":"6ed601ba_dc5258e6","in_reply_to":"e015c420_b28c4c5d","updated":"2026-07-13 12:01:30.000000000","message":"I proposed a patch to do this here: https://review.opendev.org/c/openstack/horizon/+/997013","commit_id":"ec573194de8558bdb66b0cfa31222cebb604c065"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"c69133973dfb26bb65846cb648d40cbabdbed2e3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"58185f34_2572aa28","updated":"2026-07-15 14:26:15.000000000","message":"By the way, there is a similar problem with the Users panel, but we don\u0027t have a test for it, so it\u0027s not visible through a failing test. But with this patch, the Users menu stops being visible to non-admin users.","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"17dfd3beff84e8097ae2efc760bb4e314a895ece","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":30,"id":"8cd78156_665c6c84","updated":"2026-07-17 09:56:57.000000000","message":"Hi guys,\nIt is highly possible that the failures here in the patch are not caused directly by this patch.\nSince this morning we can see the same failing test ```test_create_flavor\n``` (that probably never failed before) also in periodic job from today’s morning:\nhttps://zuul.opendev.org/t/openstack/build/7946ebe1d01247bab56fa2325ab69026\nand in recheck in completely different patch:\nhttps://review.opendev.org/c/openstack/horizon/+/986478\n\nWith completely the same symptoms:\nThe test was waiting 30s for the button ```Create Flavor``` to appear. But this button did not appear at all.\nin the Flavor tab there are missing ```check boxes``` for deleting multiple flavors at once.\nAnd also in left menu completely missing ```instances``` and ```images``` under the Admin tab.\n\nI will try to deploy fresh devstack and reproduce it in live environment.","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"796fd2558350c3c1f04ca261b54240b6309433af","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"ca9645f0_2880d255","updated":"2026-07-15 14:14:21.000000000","message":"It looks like the same policy checks are embedded in the view code: https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/identity/projects/views.py#L93-L132","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"b33410cc05245a2925b42700bb56b308c64c0ef4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"a41ed159_5a1ff0da","updated":"2026-07-21 07:18:03.000000000","message":"recheck","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"d528306801d09a7fc505ff92ff82917e22e9aeea","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"17338827_f747a08b","updated":"2026-07-24 16:56:10.000000000","message":"recheck fixc merged so let\u0027s see how it is now","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"78ed10aae3a34ddecf78414a34e035122eea00df","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"a4cfc250_98904e48","in_reply_to":"44407524_2ba54a42","updated":"2026-07-16 23:05:01.000000000","message":"The code policy enforcement looks perfect as the else part ake sure Horizon goes with the user projects list instead of list projects, which is admin only - https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/identity/projects/views.py#L116C51-L116C69\n\nKeystone default the list_user_projects to owner also - \nhttps://github.com/openstack/keystone/blob/3a7f6f86de99e69874de177148b9f386df3e0031/keystone/common/policies/project.py#L179\n\nI think something wrong and we should debug why this else condition is not satisfied when non-admin user is accessing it?","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"8d244956ad0d10f6ab98665c78f5e755c223395b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"968c02c5_73866284","in_reply_to":"489fbc42_eaa90714","updated":"2026-07-20 08:20:50.000000000","message":"Keystone has nothing to do with it, it fails at the oslo.policy call. It doesn\u0027t care about the user\u0027s project, because we are not passing it as the target when we are checking if the user has the right to list projects in general (not his own project in particular).","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"c448798a0106df810b3f8b5766c735b57063834a","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":30,"id":"e195945a_8ec1b308","in_reply_to":"8cd78156_665c6c84","updated":"2026-07-17 10:27:48.000000000","message":"Okay, it seems to me that all that you discussed here for quite some time was now changed/merged on higher level (requirements). So that is the reason why now all Horizon patches are failing with the same issue:\nhttps://review.opendev.org/c/openstack/requirements/+/996511","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"3f75a429133fc7aa947e25598fc019095fb8a5a5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"b0bc407a_e308eaab","in_reply_to":"968c02c5_73866284","updated":"2026-07-21 22:57:37.000000000","message":"well, its keystone only and oslo.policy is just a tool to enforce the policy with what target keystone sending.\n\nI am not sure why you are saying you are not passing user_id in target. you mean horizon does policy enforcement directly to oslo.policy and prepare target or just call the keystone cli and reply in the result? I think later.\n\nI can see from the code, you are sending the user_id to keystoneclient\n\n- https://github.com/openstack/horizon/blob/cd1407d4358a74fd4062953de323c029b5988339/openstack_dashboard/dashboards/identity/projects/views.py#L121\n\n- https://github.com/openstack/horizon/blob/9ca3e129ea64be0b00c81fad986a7f5ae1d2583c/openstack_dashboard/api/keystone.py#L367\n\nkeystoneclient do call the user in the base url\n- https://github.com/openstack/python-keystoneclient/blob/f44b8aead35b2731fae7577ccd038d6e3bee80fc/keystoneclient/v3/projects.py#L136\n\nthen keystone API prepare the oslo.policy target with the user_is in the target\n\n- https://github.com/openstack/keystone/blob/30ef2ffa65a3486ef882f00538e20f2253c57d4c/keystone/api/users.py#L412\n- https://github.com/openstack/keystone/blob/30ef2ffa65a3486ef882f00538e20f2253c57d4c/keystone/api/users.py#L170\n\n\u003e if the user has the right to list projects in general (not his own project in particular).\n\nthat is for list projects panel right? and not for the user\u0027s list projects (\u0027identity:list_user_projects\u0027 policy), for later one, user_id must be passed otherwise it will not get the project list for the user.","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"41720d05a7584f5549681ab9f450065e81167077","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"d8db08b9_4b524036","in_reply_to":"a4cfc250_98904e48","updated":"2026-07-17 06:53:56.000000000","message":"Because you have to be admin or domain admin to have the list_user_projects right without specified target? And since you are listing all projects, there is no target to specify.","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"8ca3604fef79803f5d4d2f9e2fdd1afdb746187b","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":30,"id":"cdb79c80_e7b016e1","in_reply_to":"b0bc407a_e308eaab","updated":"2026-07-22 20:29:37.000000000","message":"By reviewing the other change, I got the Horizon use case for the display panel. please ignore the keystoneclient example.\n\n\u003e because we are not passing it as the target when we are checking if the user has the right to list projects in general (not his own project in particular).\n\nI think the right way is to pass the user_id in target if Horizon wants to decide if the projects panel should be displayed or not. That will allow all users to display it as per the default policy, but if the operator has customized it, then it will not show.","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8648,"name":"Radomir Dopieralski","email":"openstack@dopieralski.pl","username":"thesheep"},"change_message_id":"da54092c8d4e02a9d7f421ca6947d28f783c3f3f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"44407524_2ba54a42","in_reply_to":"ca9645f0_2880d255","updated":"2026-07-15 14:27:11.000000000","message":"I can remove that policy check from the code as well, but it feels like we are missing something, and there is a problem with the policies.","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"25e10e33ad127f04fedcf9bce4da13bffd696e53","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":30,"id":"489fbc42_eaa90714","in_reply_to":"d8db08b9_4b524036","updated":"2026-07-17 19:30:08.000000000","message":"But you are passing user\u003dself.request.user.id[1], so it won\u0027t require admin access to get the user\u0027s own project list[2]. Is it failing if we do without admin? If so, then it\u0027s a bug in Keystone.\n\n[1] \nhttps://github.com/openstack/horizon/blob/cd1407d4358a74fd4062953de323c029b5988339/openstack_dashboard/dashboards/identity/projects/views.py#L121\n\nhttps://github.com/openstack/horizon/blob/cd1407d4358a74fd4062953de323c029b5988339/openstack_dashboard/api/keystone.py#L367\n\n[2] https://github.com/openstack/keystone/blob/5913588710cbf0df47057b2066243b9582e0006e/keystone/api/users.py#L415","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"},{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"efe9fe9fdab29ff3e4fbadc53958e8e5cb50a233","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":30,"id":"98587d1e_1f71ad7f","in_reply_to":"e195945a_8ec1b308","updated":"2026-07-17 10:54:58.000000000","message":"I just verified it in fresh devstack deployment, that it is not just random failure/CI issue. There are missing buttons/tabs in UI as I mentioned in previous comment.","commit_id":"2693d0934254c24fade4ba182179ad1d8081ce5f"}]}
