)]}'
{"id":"openstack%2Fkeystoneauth~1005682","triplet_id":"openstack%2Fkeystoneauth~master~Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf","project":"openstack/keystoneauth","branch":"master","topic":"fix/saml2-url-validation","attention_set":{},"removed_from_attention_set":{"7414":{"account":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"last_update":"2026-09-21 23:21:53.000000000","reason":"Change was submitted"},"15334":{"account":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"last_update":"2026-09-21 20:05:00.000000000","reason":"\u003cGERRIT_ACCOUNT_15334\u003e replied on the change","reason_account":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"}},"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-09-21 23:21:53.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf","subject":"Validate SAML2 ECP consumer fault and redirect URLs","status":"MERGED","created":"2026-09-15 09:14:22.000000000","updated":"2026-09-21 23:22:53.000000000","submitted":"2026-09-21 23:21:53.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":14,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1005682-fix/saml2-url-validation","meta_rev_id":"3c2e8bb660c377658bd818f60d63d819ef4eca23","_number":1005682,"virtual_id_number":1005682,"owner":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-09-21 23:21:52.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"all":[{"value":2,"date":"2026-09-21 20:05:00.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"all":[{"value":1,"date":"2026-09-21 20:05:00.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-15 09:35:12.000000000","updated_by":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"reviewer":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"state":"REVIEWER"},{"updated":"2026-09-15 11:11:27.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-09-16 17:18:45.000000000","updated_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"reviewer":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"state":"REVIEWER"}],"messages":[{"id":"c196bb8cd3f14cb9e92d27884333bafdd0932fc3","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:14:22.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"f892138bb1fc8249fca5f1394c4850d5814139ac","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:16:58.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"a3ea78780e4f116812418454ff166fe774e3a1b7","tag":"autogenerated:gerrit:setReadyForReview","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:17:36.000000000","message":"Set Ready For Review","accounts_in_message":[],"_revision_number":2},{"id":"c418d074b552b6eea3d04ca044257f7f3562a019","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-15 09:35:12.000000000","message":"Patch Set 2: Code-Review-1\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"6e944335ef9f6e01a9b170f0fd17cf56811f7e58","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:43:12.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":3},{"id":"c042b015038a478cc125fa562394f23cd7dbfa8a","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:43:55.000000000","message":"Patch Set 3:\n\n(3 comments)\n\nThis change is ready for review.","accounts_in_message":[],"_revision_number":3},{"id":"6857b99cc286cb1923278b59963af33fb731b217","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:44:40.000000000","message":"Patch Set 3:\n\nPatch set 3: inlined the redirect host check and expanded the comment on the conditional fault POST. Thanks.","accounts_in_message":[],"_revision_number":3},{"id":"7907818ad34731adee62a2ec3c64e49a75ea738c","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-15 11:11:27.000000000","message":"Patch Set 3: Verified-1\n\n(1 comment)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/d4e9c7d8767b447c816f8b47a373a554\n\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/18a8f1e31c2d4bf08d20f2b414245555 : SUCCESS in 1h 26m 48s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/d1c7956f2cf5467a9f3fdc148d16afa6 : FAILURE in 7m 49s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/b566e9007efb42a4b70f9d0ca564d260 : SUCCESS in 7m 09s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/a4b21a2320814dbf91e5f87261ce35e6 : SUCCESS in 6m 07s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/e545c549a9684c4080f60b615701f6f8 : SUCCESS in 10m 31s\n- openstack-tox-py315 https://zuul.opendev.org/t/openstack/build/5627cd5d53eb48ebbedf2bf8253b7619 : SUCCESS in 14m 55s (non-voting)\n- openstacksdk-functional-devstack-tips https://zuul.opendev.org/t/openstack/build/887d6369d9c642c0917e732ad94f3c2e : SUCCESS in 1h 00m 22s\n- osc-tox-py311-tips https://zuul.opendev.org/t/openstack/build/345b74401731472da96de0d78d57a4dc : SUCCESS in 4m 32s\n- osc-tox-py314-tips https://zuul.opendev.org/t/openstack/build/2c843b76876e4cc4a195a917bfd5e443 : SUCCESS in 6m 36s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/bdc13c9bdf5b44138737e332ca6ee3f8 : SUCCESS in 9m 03s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/544d170b063c43c38e8be36878f5ff67 : SUCCESS in 2m 38s","accounts_in_message":[],"_revision_number":3},{"id":"e3d014a91e42aec8c0caff2e411eb681a8c0258b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-15 21:29:29.000000000","message":"Uploaded patch set 4.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":4},{"id":"184bf6ade3733a117566501f500ff4e9212cdb6a","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-15 21:30:15.000000000","message":"Patch Set 4: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"d0146337aa225495bf6f955506ac361f8d8da79d","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-15 22:49:12.000000000","message":"Patch Set 4: Verified-1\n\n(2 comments)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/53ad0b07907d49a1b05654a6ded3f020\n\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/6303dc1e2e24480a94cc4d340c42bd01 : SUCCESS in 1h 17m 33s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a0071a570bef4c6d840fd473d468f4f6 : FAILURE in 5m 46s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/e3c459c23f6d43e7a8a02b69e09e3403 : SUCCESS in 4m 47s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/83bf9d35a99641b1816f1bb12603e52f : SUCCESS in 7m 08s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/8a4380a4913547dfa2d15f6c5f8d58da : SUCCESS in 10m 12s\n- openstack-tox-py315 https://zuul.opendev.org/t/openstack/build/550597a593fe4c66b30953ea34b5df5a : SUCCESS in 15m 41s (non-voting)\n- openstacksdk-functional-devstack-tips https://zuul.opendev.org/t/openstack/build/62e3fba71002438282bd19206a22d2d6 : SUCCESS in 1h 03m 06s\n- osc-tox-py311-tips https://zuul.opendev.org/t/openstack/build/f8dc94559fab46f7a26f78c3c1359404 : SUCCESS in 4m 55s\n- osc-tox-py314-tips https://zuul.opendev.org/t/openstack/build/b7b29e2528be4011bafe22aac5f19c3b : SUCCESS in 7m 38s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/047c733861da47f09fb1ce20be9c77ea : SUCCESS in 8m 00s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3c9b4966fe2a460e81194fa51b47fe88 : SUCCESS in 4m 32s","accounts_in_message":[],"_revision_number":4},{"id":"26f103558af1003bfea930063f58d024787ca18b","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-09-16 17:18:45.000000000","message":"Patch Set 4: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"511ca9308cb2f1034befc9158e3b1e890ae04253","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-16 18:56:17.000000000","message":"Patch Set 4:\n\n(2 comments)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/aa05e03ba03442c6b6c230b0a2fd94a3\n\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/5c6099335f1045c397c0d81b9d235344 : SUCCESS in 1h 30m 23s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/4f66da8fa28e4d339237720dedd33aeb : FAILURE in 8m 11s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/a7d2a71f6cd14d82bff91799e16592ce : SUCCESS in 6m 46s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/bf605d90455040a28d3672f21fe5338f : SUCCESS in 3m 53s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/233d43cb7cdf41ac9a34d37c248b3bb6 : SUCCESS in 9m 35s\n- openstack-tox-py315 https://zuul.opendev.org/t/openstack/build/73fa8e7b303047258bb40b6838702b34 : SUCCESS in 15m 01s (non-voting)\n- openstacksdk-functional-devstack-tips https://zuul.opendev.org/t/openstack/build/8507f5d62bb04c10b65e07499166a81e : SUCCESS in 29m 12s\n- osc-tox-py311-tips https://zuul.opendev.org/t/openstack/build/d86451bf0f744f6fb02bb8c3b07b8518 : SUCCESS in 4m 34s\n- osc-tox-py314-tips https://zuul.opendev.org/t/openstack/build/8b914ae411bb46dfb59224dd60075311 : SUCCESS in 7m 40s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/67446ce550144fa0bd77da5a05515598 : SUCCESS in 9m 09s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/5d3e99995ab74948a53465987dd6a656 : SUCCESS in 5m 23s","accounts_in_message":[],"_revision_number":4},{"id":"b0ad300c5f1d26baee1c6c2e835b85e99c950ad9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-21 20:04:45.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified-1 (copy condition: \"NEVER\")\n* Workflow+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"38c12b634a0f3e2f11848189c95cd2cac31cc40a","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-21 20:05:00.000000000","message":"Patch Set 5: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"e117ca3987b32a1b604561fc15507d725faa66f3","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-21 21:44:00.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/7e3c361caec140f88628b5dfdea5dc1c\n\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/991b471a014c42fba2089fcdff9add5d : SUCCESS in 1h 33m 02s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/87844b8735f246bda960ec60a44ccee9 : SUCCESS in 8m 19s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/51572ebf9fae48ec97a8c327f2587be0 : SUCCESS in 8m 17s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/796d94a35b0c4d32ac40d88f6d00e463 : SUCCESS in 4m 29s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/9ac588fd807b464cbb1b5ed11115f84d : SUCCESS in 5m 52s\n- openstack-tox-py315 https://zuul.opendev.org/t/openstack/build/6d31a37a764d46ce82f053014e68a835 : SUCCESS in 7m 19s (non-voting)\n- openstacksdk-functional-devstack-tips https://zuul.opendev.org/t/openstack/build/383695a14e464398a972da757aaa7d24 : SUCCESS in 32m 20s\n- osc-tox-py311-tips https://zuul.opendev.org/t/openstack/build/16f7d34dd3fa4ecfb0c96c314d2ae291 : SUCCESS in 6m 17s\n- osc-tox-py314-tips https://zuul.opendev.org/t/openstack/build/78ef571dd4df49e3b73d70f68c7264cd : SUCCESS in 7m 13s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ebf3763e83c1477f91ac7d02a5c256fe : SUCCESS in 5m 20s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ab3c00a043aa47dd94283057827c1d0e : SUCCESS in 6m 15s","accounts_in_message":[],"_revision_number":5},{"id":"edc5eada1013682a8a3091626f42fc67ee32f935","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-21 21:46:00.000000000","message":"Patch Set 5: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":5},{"id":"44d38d408bc9ddf6b153bac4296c0ca383267c6c","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-21 23:21:52.000000000","message":"Patch Set 5: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/16853701420545efae61b276276c5213\n\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/523088e574ea4e94a85131badd273b6a : SUCCESS in 1h 29m 18s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/2ddd21bc0a554a6b8a4319c06754e803 : SUCCESS in 9m 14s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/bc8cd1faf3cc4d1f8695b2f3265a5398 : SUCCESS in 6m 56s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/4e218e57cd004a42be3a6ee0c63166b4 : SUCCESS in 5m 09s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/e2ab866c804348f4aec9724aedcc4cc5 : SUCCESS in 10m 05s\n- openstacksdk-functional-devstack-tips https://zuul.opendev.org/t/openstack/build/30aebabd4fbc48108cf3d0900aec211b : SUCCESS in 40m 17s\n- osc-tox-py311-tips https://zuul.opendev.org/t/openstack/build/9038eda1a94e455fb977dd8f30697d01 : SUCCESS in 5m 05s\n- osc-tox-py314-tips https://zuul.opendev.org/t/openstack/build/e48a8f3ddff249c09c14a7a76cce535b : SUCCESS in 4m 47s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a6d32adb96da4521b54ef541de6d8ef9 : SUCCESS in 10m 08s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/bf1d4334e007455a91d8b8021c4467d3 : SUCCESS in 4m 22s","accounts_in_message":[],"_revision_number":5},{"id":"af906d242d580830f7d3997ac5264cedb88f4a5b","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-21 23:21:53.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":5},{"id":"3c2e8bb660c377658bd818f60d63d819ef4eca23","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-21 23:22:53.000000000","message":"Patch Set 5:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/6254fdb2126e40c799bad3ea910d9a61\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d02d9df897804485b6df1375bd30180c : SUCCESS in 45s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/dd9f58c9af024905b549b8edb2394ff3 : SUCCESS in 47s","accounts_in_message":[],"_revision_number":5}],"current_revision_number":5,"current_revision":"d53bdd74d75013b800ceb64373b6cc9e8a055feb","revisions":{"67ac4f550460855451a6f2df21fda68b23b5b522":{"kind":"REWORK","_number":1,"created":"2026-09-15 09:14:22.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/82/1005682/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/82/1005682/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/1"}}},"commit":{"parents":[{"commit":"ac0679fc8a611fd2a8984fcc5e6c2474caf9d355","subject":"typing: Remove unnecessary use of TYPE_CHECKING","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/ac0679fc8a611fd2a8984fcc5e6c2474caf9d355"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:14:08.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:14:15.000000000","tz":120},"subject":"Validate SAML2 ECP consumer fault and redirect URLs","message":"Validate SAML2 ECP consumer fault and redirect URLs\n\nThe SAML2 ECP auth hook POSTs a SOAP fault to responseConsumerURL on\nconsumer mismatch and follows ACS 302/303 Location headers without\nchecking that those targets share a host with the original federation\nrequest. A malicious Location can forward federation session cookies to\nan unexpected host.\n\nOnly send the mismatch fault when responseConsumerURL matches the\noriginal request netloc, and reject cross-host ACS redirects.\n\nCloses-Bug: #2167316\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/67ac4f550460855451a6f2df21fda68b23b5b522"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/67ac4f550460855451a6f2df21fda68b23b5b522"}]},"branch":"refs/heads/master"},"bdd13d481dec02911a3ac80b9c0807e7711e6e08":{"kind":"REWORK","_number":2,"created":"2026-09-15 09:16:58.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/82/1005682/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/82/1005682/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/2"}}},"commit":{"parents":[{"commit":"ac0679fc8a611fd2a8984fcc5e6c2474caf9d355","subject":"typing: Remove unnecessary use of TYPE_CHECKING","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/ac0679fc8a611fd2a8984fcc5e6c2474caf9d355"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:14:08.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:16:53.000000000","tz":120},"subject":"Validate SAML2 ECP consumer fault and redirect URLs","message":"Validate SAML2 ECP consumer fault and redirect URLs\n\nThe SAML2 ECP auth hook POSTs a SOAP fault to responseConsumerURL on\nconsumer mismatch and follows ACS 302/303 Location headers without\nchecking that those targets share a host with the original federation\nrequest. A malicious Location can forward federation session cookies to\nan unexpected host.\n\nOnly send the mismatch fault when responseConsumerURL matches the\noriginal request netloc, and reject cross-host ACS redirects.\n\nCloses-Bug: #2167316\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/bdd13d481dec02911a3ac80b9c0807e7711e6e08"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/bdd13d481dec02911a3ac80b9c0807e7711e6e08"}]},"branch":"refs/heads/master"},"250754a7e08e8759110e1750a510d930f2db8fbe":{"kind":"REWORK","_number":3,"created":"2026-09-15 09:43:12.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/82/1005682/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/82/1005682/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/3"}}},"commit":{"parents":[{"commit":"ac0679fc8a611fd2a8984fcc5e6c2474caf9d355","subject":"typing: Remove unnecessary use of TYPE_CHECKING","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/ac0679fc8a611fd2a8984fcc5e6c2474caf9d355"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:14:08.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:43:07.000000000","tz":120},"subject":"Validate SAML2 ECP consumer fault and redirect URLs","message":"Validate SAML2 ECP consumer fault and redirect URLs\n\nThe SAML2 ECP auth hook POSTs a SOAP fault to responseConsumerURL on\nconsumer mismatch and follows ACS 302/303 Location headers without\nchecking that those targets share a host with the original federation\nrequest. A malicious Location can forward federation session cookies to\nan unexpected host.\n\nOnly send the mismatch fault when responseConsumerURL matches the\noriginal request netloc, and reject cross-host ACS redirects.\n\nCloses-Bug: #2167316\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/250754a7e08e8759110e1750a510d930f2db8fbe"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/250754a7e08e8759110e1750a510d930f2db8fbe"}]},"branch":"refs/heads/master"},"43561c5f2285cb1d1c8bbcc8e433f82e616a6995":{"kind":"REWORK","_number":4,"created":"2026-09-15 21:29:29.000000000","uploader":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"ref":"refs/changes/82/1005682/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/82/1005682/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/4"}}},"commit":{"parents":[{"commit":"8980efafacd178f72e5e407e29743872280e5667","subject":"trivial: Remove type info from docstrings","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/8980efafacd178f72e5e407e29743872280e5667"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:14:08.000000000","tz":120},"committer":{"name":"Stephen Finucane","email":"stephenfin@redhat.com","date":"2026-09-15 21:27:52.000000000","tz":60},"subject":"Validate SAML2 ECP consumer fault and redirect URLs","message":"Validate SAML2 ECP consumer fault and redirect URLs\n\nThe SAML2 ECP auth hook POSTs a SOAP fault to responseConsumerURL on\nconsumer mismatch and follows ACS 302/303 Location headers without\nchecking that those targets share a host with the original federation\nrequest. A malicious Location can forward federation session cookies to\nan unexpected host.\n\nOnly send the mismatch fault when responseConsumerURL matches the\noriginal request netloc, and reject cross-host ACS redirects.\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nCloses-Bug: #2167316\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/43561c5f2285cb1d1c8bbcc8e433f82e616a6995"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/43561c5f2285cb1d1c8bbcc8e433f82e616a6995"}]},"branch":"refs/heads/master"},"d53bdd74d75013b800ceb64373b6cc9e8a055feb":{"kind":"REWORK","_number":5,"created":"2026-09-21 20:04:45.000000000","uploader":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"ref":"refs/changes/82/1005682/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/82/1005682/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/82/1005682/5"}}},"commit":{"parents":[{"commit":"be20882300587c6afb3a5e04c92a7f066698ebb3","subject":"Merge \"Redact OTP and MFA fields in OIDC debug sanitization\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/be20882300587c6afb3a5e04c92a7f066698ebb3"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:14:08.000000000","tz":120},"committer":{"name":"Stephen Finucane","email":"stephenfin@redhat.com","date":"2026-09-21 20:04:16.000000000","tz":60},"subject":"Validate SAML2 ECP consumer fault and redirect URLs","message":"Validate SAML2 ECP consumer fault and redirect URLs\n\nThe SAML2 ECP auth hook POSTs a SOAP fault to responseConsumerURL on\nconsumer mismatch and follows ACS 302/303 Location headers without\nchecking that those targets share a host with the original federation\nrequest. A malicious Location can forward federation session cookies to\nan unexpected host.\n\nOnly send the mismatch fault when responseConsumerURL matches the\noriginal request netloc, and reject cross-host ACS redirects.\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nCloses-Bug: #2167316\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/d53bdd74d75013b800ceb64373b6cc9e8a055feb"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/d53bdd74d75013b800ceb64373b6cc9e8a055feb"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
