)]}'
{"specs/keystone/ongoing/external-pdp-for-keystone.rst":[{"author":{"_account_id":10608,"name":"Matthew Edmonds","email":"edmondsw@us.ibm.com","username":"edmondsw"},"change_message_id":"33ca98f6235a23286a9ac8a8cc0f0dbd5a224827","unresolved":false,"context_lines":[{"line_number":26,"context_line":"to an external authorization policy engine."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"Existing works [Fortress_, Moon_] show the feasibility of this approach with the Fortress and Moon policy engines."},{"line_number":29,"context_line":"This spepcification proposes a generic hook which will re-direct authorization requests"},{"line_number":30,"context_line":"to an external PDP instead of using the native one."},{"line_number":31,"context_line":"Each policy engine stores and manages related information of their policy, "},{"line_number":32,"context_line":"grants or denies requests based on these information and their own rules."}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f436f4f_e6605535","line":29,"range":{"start_line":29,"start_character":5,"end_line":29,"end_character":19},"updated":"2017-08-09 16:35:47.000000000","message":"nit: spelling","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":12342,"name":"WuKong","email":"rebirthmonkey@gmail.com","username":"RHE"},"change_message_id":"6748b6ebba10e8a75604be82d42e1ce965539c5e","unresolved":false,"context_lines":[{"line_number":26,"context_line":"to an external authorization policy engine."},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"Existing works [Fortress_, Moon_] show the feasibility of this approach with the Fortress and Moon policy engines."},{"line_number":29,"context_line":"This spepcification proposes a generic hook which will re-direct authorization requests"},{"line_number":30,"context_line":"to an external PDP instead of using the native one."},{"line_number":31,"context_line":"Each policy engine stores and manages related information of their policy, "},{"line_number":32,"context_line":"grants or denies requests based on these information and their own rules."}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_f0d403eb","line":29,"range":{"start_line":29,"start_character":5,"end_line":29,"end_character":19},"in_reply_to":"9f436f4f_e6605535","updated":"2017-08-29 13:43:44.000000000","message":"Hi Matthew, \nfor your information, since this topic is now moved to oslo.policy, a new spec here created: https://review.openstack.org/#/c/492543/. \nAll your comments here are taken into account in the new spec. Your future comments are very welcome!","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":10608,"name":"Matthew Edmonds","email":"edmondsw@us.ibm.com","username":"edmondsw"},"change_message_id":"33ca98f6235a23286a9ac8a8cc0f0dbd5a224827","unresolved":false,"context_lines":[{"line_number":41,"context_line":"he/she must update the policy.yaml file for each component (Nova, Glance, Neutron, ...)."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"The only authorization model allowed is based on a RBAC model (Role Based Access Control) and the operator cannot modify"},{"line_number":44,"context_line":"this model. But in some case, he/she may want to add new information like domain membership and authorize"},{"line_number":45,"context_line":"actions in his/her platform based on his membership."},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"The policy modification must be done on all component with the risk of error appearing."},{"line_number":48,"context_line":"The policy modification is not centralized."}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f436f4f_66734517","line":45,"range":{"start_line":44,"start_character":38,"end_line":45,"end_character":51},"updated":"2017-08-09 16:35:47.000000000","message":"if you\u0027re talking about keystone domains, I\u0027m not sure how this helps with that. Can\u0027t you already check domain membership info from the token with policy.json/yaml if you want to do that?","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":41,"context_line":"he/she must update the policy.yaml file for each component (Nova, Glance, Neutron, ...)."},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"The only authorization model allowed is based on a RBAC model (Role Based Access Control) and the operator cannot modify"},{"line_number":44,"context_line":"this model. But in some case, he/she may want to add new information like domain membership and authorize"},{"line_number":45,"context_line":"actions in his/her platform based on his membership."},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"The policy modification must be done on all component with the risk of error appearing."},{"line_number":48,"context_line":"The policy modification is not centralized."}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_c45fb70c","line":45,"range":{"start_line":44,"start_character":38,"end_line":45,"end_character":51},"in_reply_to":"9f436f4f_66734517","updated":"2017-08-22 15:38:51.000000000","message":"If there is a specific non-RBAC model you have in mind, it would be useful to have a more detailed example of how that model would interface with oslo.policy\u0027s rule evaluation system.","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":53,"context_line":"This change proposes to allow users to chose their PDP (Policy Decision Point)."},{"line_number":54,"context_line":"User will be able to choose between:"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":"* standard local policy.yaml file"},{"line_number":57,"context_line":"* Fortress platform"},{"line_number":58,"context_line":"* Moon platform"},{"line_number":59,"context_line":"* ..."}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_49a3e250","line":56,"updated":"2017-08-22 15:38:51.000000000","message":"The default policies are moving into code (see https://governance.openstack.org/tc/goals/queens/policy-in-code.html). This proposal needs to take that change into account.","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":10608,"name":"Matthew Edmonds","email":"edmondsw@us.ibm.com","username":"edmondsw"},"change_message_id":"33ca98f6235a23286a9ac8a8cc0f0dbd5a224827","unresolved":false,"context_lines":[{"line_number":61,"context_line":"The switch between those PDP can be configured and done in Oslo_policy thus every components that use Oslo_Policy"},{"line_number":62,"context_line":"can benefit this improvement."},{"line_number":63,"context_line":""},{"line_number":64,"context_line":"To be able to communicate with one of those PDP, Oslo_Policy must use a dedicated API to talk to each PDP."},{"line_number":65,"context_line":"This API can be as simple as:"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":".. code:: javascript"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f436f4f_e6185582","line":64,"range":{"start_line":64,"start_character":49,"end_line":64,"end_character":105},"updated":"2017-08-09 16:35:47.000000000","message":"you\u0027re talking about the API of the PDPs, not a new OpenStack API, right? I assume each PDP has a different API, so how will oslo know the different APIs (some kind of plugin mechanism to add support for different PDPs?) and which one to use in a particular situation (conf option indicates PDP type?)?","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":61,"context_line":"The switch between those PDP can be configured and done in Oslo_policy thus every components that use Oslo_Policy"},{"line_number":62,"context_line":"can benefit this improvement."},{"line_number":63,"context_line":""},{"line_number":64,"context_line":"To be able to communicate with one of those PDP, Oslo_Policy must use a dedicated API to talk to each PDP."},{"line_number":65,"context_line":"This API can be as simple as:"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":".. code:: javascript"}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_e4499360","line":64,"range":{"start_line":64,"start_character":49,"end_line":64,"end_character":105},"in_reply_to":"9f436f4f_e6185582","updated":"2017-08-22 15:38:51.000000000","message":"Yes, we need this spec to include much more detail about how the PDP will be selected and how oslo.policy will know to consult the PDP instead of using the built-in rules.","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":66,"context_line":""},{"line_number":67,"context_line":".. code:: javascript"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"    GET /authz/\u003cPROJECT_ID\u003e/\u003cSUBJECT_ID\u003e/\u003cOBJECT_ID\u003e/\u003cACTION_ID\u003e"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"Where:"},{"line_number":72,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_295f7642","line":69,"updated":"2017-08-22 15:38:51.000000000","message":"oslo.policy already supports http check rules. https://docs.openstack.org/oslo.policy/latest/reference/api/oslo_policy.policy.html#http-check","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":10608,"name":"Matthew Edmonds","email":"edmondsw@us.ibm.com","username":"edmondsw"},"change_message_id":"33ca98f6235a23286a9ac8a8cc0f0dbd5a224827","unresolved":false,"context_lines":[{"line_number":72,"context_line":""},{"line_number":73,"context_line":"* `PROJECT_ID` is the identification of the Keystone project where the object is"},{"line_number":74,"context_line":"* `SUBJECT_ID` is the identification of the user asking the action"},{"line_number":75,"context_line":"* `OBJECT_ID` is the identification of the object targeted by the action"},{"line_number":76,"context_line":"* `ACTION_ID` is the identification of the action of the user on the object"},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"For example, here are some possible requests:"}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f436f4f_e974a69b","line":75,"updated":"2017-08-09 16:35:47.000000000","message":"I\u0027m not sure oslo.policy knows an object_id. And some ids are only unique for that type of object, not for all object types. So I\u0027m not sure this will work without changes in the various OpenStack components. It also not sure how this id would be useful to the PDP...","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":72,"context_line":""},{"line_number":73,"context_line":"* `PROJECT_ID` is the identification of the Keystone project where the object is"},{"line_number":74,"context_line":"* `SUBJECT_ID` is the identification of the user asking the action"},{"line_number":75,"context_line":"* `OBJECT_ID` is the identification of the object targeted by the action"},{"line_number":76,"context_line":"* `ACTION_ID` is the identification of the action of the user on the object"},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"For example, here are some possible requests:"}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_c473374d","line":75,"in_reply_to":"9f436f4f_e974a69b","updated":"2017-08-22 15:38:51.000000000","message":"How will the PDP know what operations a user can perform on a given object?","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":10608,"name":"Matthew Edmonds","email":"edmondsw@us.ibm.com","username":"edmondsw"},"change_message_id":"33ca98f6235a23286a9ac8a8cc0f0dbd5a224827","unresolved":false,"context_lines":[{"line_number":73,"context_line":"* `PROJECT_ID` is the identification of the Keystone project where the object is"},{"line_number":74,"context_line":"* `SUBJECT_ID` is the identification of the user asking the action"},{"line_number":75,"context_line":"* `OBJECT_ID` is the identification of the object targeted by the action"},{"line_number":76,"context_line":"* `ACTION_ID` is the identification of the action of the user on the object"},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"For example, here are some possible requests:"},{"line_number":79,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f436f4f_c9ae82e6","line":76,"updated":"2017-08-09 16:35:47.000000000","message":"I assume you mean to use the policy rule for this? I believe the Fortress patch had tried to parse that rule, and I don\u0027t know that that works for all OpenStack projects, since they are not consistent in the format of the rules they define, so please be conscious of that.","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":91,"context_line":"Alternatives"},{"line_number":92,"context_line":"------------"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"None"},{"line_number":95,"context_line":""},{"line_number":96,"context_line":"Security Impact"},{"line_number":97,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_440d0736","line":94,"updated":"2017-08-22 15:38:51.000000000","message":"Please add more detail here exploring how the existing http check could be used to achieve this goal, or how it does not support what is needed. If it does not support what is needed, could we extend it in some way?","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"e2944fdbdbfb2c16e3cae6c608bd831754ff44c8","unresolved":false,"context_lines":[{"line_number":91,"context_line":"Alternatives"},{"line_number":92,"context_line":"------------"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"None"},{"line_number":95,"context_line":""},{"line_number":96,"context_line":"Security Impact"},{"line_number":97,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_dfc5415d","line":94,"in_reply_to":"7f287b81_440d0736","updated":"2017-08-22 18:07:02.000000000","message":"You could also discuss building a tool to generate policy YAML files by reading rules from backend systems. That would eliminate some of the performance issues with the proposed approach, but still allow for centralized management of the policies.","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":92,"context_line":"------------"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"None"},{"line_number":95,"context_line":""},{"line_number":96,"context_line":"Security Impact"},{"line_number":97,"context_line":"---------------"},{"line_number":98,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_a404abc7","line":95,"updated":"2017-08-22 15:38:51.000000000","message":"Are there existing libraries that abstract the different PDP backends already, or are we going to have to build that abstraction into oslo.policy?","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":105,"context_line":"The only data which could be listened by malicious sniffers will be :"},{"line_number":106,"context_line":""},{"line_number":107,"context_line":"* the Keystone project ID"},{"line_number":108,"context_line":"* the user ID"},{"line_number":109,"context_line":"* the object targeted by the action"},{"line_number":110,"context_line":"* the action of the user on the object"},{"line_number":111,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_041edf0b","line":108,"updated":"2017-08-22 15:38:51.000000000","message":"User identity now includes more information than these 2 values, so we should include it all.","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":106,"context_line":""},{"line_number":107,"context_line":"* the Keystone project ID"},{"line_number":108,"context_line":"* the user ID"},{"line_number":109,"context_line":"* the object targeted by the action"},{"line_number":110,"context_line":"* the action of the user on the object"},{"line_number":111,"context_line":""},{"line_number":112,"context_line":"Tokens, keys and other sensitive data will not be exposed."}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_a4894b27","line":109,"updated":"2017-08-22 15:38:51.000000000","message":"Unless the object is only ever identified by UUID, this value would be something the user has control over, and could open the PDP to injection attacks.","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":2472,"name":"Doug Hellmann","email":"dhellmann@redhat.com","username":"doug-hellmann"},"change_message_id":"634b0a6e96f9f5835a60d1cf2726937126c636e2","unresolved":false,"context_lines":[{"line_number":107,"context_line":"* the Keystone project ID"},{"line_number":108,"context_line":"* the user ID"},{"line_number":109,"context_line":"* the object targeted by the action"},{"line_number":110,"context_line":"* the action of the user on the object"},{"line_number":111,"context_line":""},{"line_number":112,"context_line":"Tokens, keys and other sensitive data will not be exposed."},{"line_number":113,"context_line":"No API change is required by this change."}],"source_content_type":"text/x-rst","patch_set":1,"id":"7f287b81_4413c70e","line":110,"updated":"2017-08-22 15:38:51.000000000","message":"Are all of those pieces of information actually available when a policy rule is being evaluated?","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"},{"author":{"_account_id":10608,"name":"Matthew Edmonds","email":"edmondsw@us.ibm.com","username":"edmondsw"},"change_message_id":"33ca98f6235a23286a9ac8a8cc0f0dbd5a224827","unresolved":false,"context_lines":[{"line_number":123,"context_line":"Notifications Impact"},{"line_number":124,"context_line":"--------------------"},{"line_number":125,"context_line":""},{"line_number":126,"context_line":"**TODO**: We don\u0027t understand what are notifications here..."},{"line_number":127,"context_line":""},{"line_number":128,"context_line":"Please specify any changes to notifications. Be that an extra notification,"},{"line_number":129,"context_line":"changes to an existing notification, or removing a notification."}],"source_content_type":"text/x-rst","patch_set":1,"id":"9f436f4f_a6aecd2b","line":126,"updated":"2017-08-09 16:35:47.000000000","message":"should be \"None\"","commit_id":"1bfcb18e94b3b6f5c1793110079d438e36dfc804"}]}
