)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2bdfd327147dfae9a832fddbd0e514636aa84015","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"65ee2490_52422680","updated":"2026-08-06 16:52:24.000000000","message":"recheck failure was caused by a known problem with git server.","commit_id":"454e43e2cdb8afc2ee0ae2bf16dc07a781358263"},{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"209594e9c1397cbb932a4fb53b552f2e2f199144","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":8,"id":"e29bae07_ef45ffc8","updated":"2026-08-24 11:12:04.000000000","message":"Hi @kajinamit@oss.nttdata.com, @gmaan.os14@gmail.com, I am not sure if you are in touch/coordinating your patches. But It seems to me they are in a conflict right now. And both pointing to ```Closes-Bug: #2161292``` that is already closed for Horizon.\nI think that 999879 should be merged first and then 927342 rebased on top (which will probably require fixing some conflicts around InvalidScope). Or changes from 999879 could be probably included into 927342.","commit_id":"f59f66152e7a4930466e97ae1cf2a205827e4f13"}],"doc/source/configuration/settings.rst":[{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"833f114fbdb85f9640926ca505061af4f013b6a6","unresolved":true,"context_lines":[{"line_number":1582,"context_line":""},{"line_number":1583,"context_line":".. versionadded:: 2026.1(Gazpacho)"},{"line_number":1584,"context_line":""},{"line_number":1585,"context_line":".. versionchanged:: 2026.2(Epoxy)"},{"line_number":1586,"context_line":""},{"line_number":1587,"context_line":"   The default value was changed to `False`"},{"line_number":1588,"context_line":""}],"source_content_type":"text/x-rst","patch_set":6,"id":"919bb652_14fa3c33","line":1585,"range":{"start_line":1585,"start_character":27,"end_line":1585,"end_character":32},"updated":"2026-08-20 12:38:42.000000000","message":"2026.2 is Hibiscus","commit_id":"454e43e2cdb8afc2ee0ae2bf16dc07a781358263"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"df5b81703254a5ac3ebd2e730ab3cccfdb5e47f8","unresolved":false,"context_lines":[{"line_number":1582,"context_line":""},{"line_number":1583,"context_line":".. versionadded:: 2026.1(Gazpacho)"},{"line_number":1584,"context_line":""},{"line_number":1585,"context_line":".. versionchanged:: 2026.2(Epoxy)"},{"line_number":1586,"context_line":""},{"line_number":1587,"context_line":"   The default value was changed to `False`"},{"line_number":1588,"context_line":""}],"source_content_type":"text/x-rst","patch_set":6,"id":"ddeb3e34_1bfd2edb","line":1585,"range":{"start_line":1585,"start_character":27,"end_line":1585,"end_character":32},"in_reply_to":"919bb652_14fa3c33","updated":"2026-08-20 13:44:02.000000000","message":"Done","commit_id":"454e43e2cdb8afc2ee0ae2bf16dc07a781358263"},{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"833f114fbdb85f9640926ca505061af4f013b6a6","unresolved":true,"context_lines":[{"line_number":1586,"context_line":""},{"line_number":1587,"context_line":"   The default value was changed to `False`"},{"line_number":1588,"context_line":""},{"line_number":1589,"context_line":".. deprecated:: 2026.2(Epoxy)"},{"line_number":1590,"context_line":""},{"line_number":1591,"context_line":"   Setting this option to True is known to break keystone API access due to"},{"line_number":1592,"context_line":"   keystone not allowing all administrator operations for domain admin."}],"source_content_type":"text/x-rst","patch_set":6,"id":"2aa3e2fc_bac87b44","line":1589,"range":{"start_line":1589,"start_character":23,"end_line":1589,"end_character":28},"updated":"2026-08-20 12:38:42.000000000","message":"ditto","commit_id":"454e43e2cdb8afc2ee0ae2bf16dc07a781358263"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"df5b81703254a5ac3ebd2e730ab3cccfdb5e47f8","unresolved":false,"context_lines":[{"line_number":1586,"context_line":""},{"line_number":1587,"context_line":"   The default value was changed to `False`"},{"line_number":1588,"context_line":""},{"line_number":1589,"context_line":".. deprecated:: 2026.2(Epoxy)"},{"line_number":1590,"context_line":""},{"line_number":1591,"context_line":"   Setting this option to True is known to break keystone API access due to"},{"line_number":1592,"context_line":"   keystone not allowing all administrator operations for domain admin."}],"source_content_type":"text/x-rst","patch_set":6,"id":"0ed01056_c7d3aaea","line":1589,"range":{"start_line":1589,"start_character":23,"end_line":1589,"end_character":28},"in_reply_to":"2aa3e2fc_bac87b44","updated":"2026-08-20 13:44:02.000000000","message":"Done","commit_id":"454e43e2cdb8afc2ee0ae2bf16dc07a781358263"}],"openstack_auth/policy.py":[{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"833f114fbdb85f9640926ca505061af4f013b6a6","unresolved":true,"context_lines":[{"line_number":272,"context_line":"            credentials,"},{"line_number":273,"context_line":"            do_raise\u003dTrue,"},{"line_number":274,"context_line":"        )"},{"line_number":275,"context_line":"    except policy.InvalidScope:"},{"line_number":276,"context_line":"        # Ignore oslo.policy token scope checks."},{"line_number":277,"context_line":"        allowed \u003d True"},{"line_number":278,"context_line":"    except policy.PolicyNotAuthorized:"},{"line_number":279,"context_line":"        allowed \u003d False"},{"line_number":280,"context_line":"    if not allowed:"}],"source_content_type":"text/x-python","patch_set":6,"id":"c999b61a_f1e3f2ae","side":"PARENT","line":277,"range":{"start_line":275,"start_character":0,"end_line":277,"end_character":22},"updated":"2026-08-20 12:38:42.000000000","message":"Hello @kajinamit@oss.nttdata.com, thank you for the patch!\n\nI believe ```OPENSTACK_KEYSTONE_PREFER_DOMAIN_TOKEN \u003d False``` is the right default.\nI am less sure about removing the ```InvalidScope``` handling in ```_check_credentials()```. Before this patch, a scope mismatch did not crash Horizon, it was caught and the check continued. After this patch, if ```oslo.policy``` raises ```InvalidScope```, nothing catches it.\nThe option is still settable, and when both ```OPENSTACK_KEYSTONE_PREFER_DOMAIN_TOKEN \u003d True``` and ```OPENSTACK_KEYSTONE_MULTIDOMAIN_SUPPORT \u003d True```, the identity policy path uses domain credentials first. If a Keystone rule does not allow domain scope, ```oslo.policy``` raises ```InvalidScope```, which is no longer handled, and the page can crash.\n\nI see the release note that changing this option is known to break Keystone operations such as identity provider, that makes sense for the default change to False. My concern is if an operator still sets True, uncaught ```InvalidScope``` in ```_check_credentials()``` can crash Horizon during policy checks, not just fail at the Keystone API.\n\nAm I missing something?","commit_id":"abd62f7a54ef0391aa075363b6e934719061e107"},{"author":{"_account_id":35133,"name":"Jan Jasek","email":"jjasek@redhat.com","username":"janjasek"},"change_message_id":"209594e9c1397cbb932a4fb53b552f2e2f199144","unresolved":false,"context_lines":[{"line_number":272,"context_line":"            credentials,"},{"line_number":273,"context_line":"            do_raise\u003dTrue,"},{"line_number":274,"context_line":"        )"},{"line_number":275,"context_line":"    except policy.InvalidScope:"},{"line_number":276,"context_line":"        # Ignore oslo.policy token scope checks."},{"line_number":277,"context_line":"        allowed \u003d True"},{"line_number":278,"context_line":"    except policy.PolicyNotAuthorized:"},{"line_number":279,"context_line":"        allowed \u003d False"},{"line_number":280,"context_line":"    if not allowed:"}],"source_content_type":"text/x-python","patch_set":6,"id":"8384c1e2_dccb218e","side":"PARENT","line":277,"range":{"start_line":275,"start_character":0,"end_line":277,"end_character":22},"in_reply_to":"75d9f7d6_ec4eb63c","updated":"2026-08-24 11:12:04.000000000","message":"Done","commit_id":"abd62f7a54ef0391aa075363b6e934719061e107"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"df5b81703254a5ac3ebd2e730ab3cccfdb5e47f8","unresolved":true,"context_lines":[{"line_number":272,"context_line":"            credentials,"},{"line_number":273,"context_line":"            do_raise\u003dTrue,"},{"line_number":274,"context_line":"        )"},{"line_number":275,"context_line":"    except policy.InvalidScope:"},{"line_number":276,"context_line":"        # Ignore oslo.policy token scope checks."},{"line_number":277,"context_line":"        allowed \u003d True"},{"line_number":278,"context_line":"    except policy.PolicyNotAuthorized:"},{"line_number":279,"context_line":"        allowed \u003d False"},{"line_number":280,"context_line":"    if not allowed:"}],"source_content_type":"text/x-python","patch_set":6,"id":"75d9f7d6_ec4eb63c","side":"PARENT","line":277,"range":{"start_line":275,"start_character":0,"end_line":277,"end_character":22},"in_reply_to":"c999b61a_f1e3f2ae","updated":"2026-08-20 13:44:02.000000000","message":"Oh. That\u0027s a good point. I\u0027ve updated the change to handle InvalidScope in a better way so that horizon doesn\u0027t crash.","commit_id":"abd62f7a54ef0391aa075363b6e934719061e107"}]}
