)]}'
{"id":"openstack%2Fkeystoneauth~1005691","triplet_id":"openstack%2Fkeystoneauth~master~I96b14110c0786d92b87df45a8407699ef733a130","project":"openstack/keystoneauth","branch":"master","topic":"fix/saml2-ecp-robustness","attention_set":{"15334":{"account":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"last_update":"2026-09-15 22:16:57.000000000","reason":"A robot voted negatively on a label"},"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-09-15 22:16:57.000000000","reason":"A robot voted negatively on a label"}},"removed_from_attention_set":{},"hashtags":[],"change_id":"I96b14110c0786d92b87df45a8407699ef733a130","subject":"Handle optional RelayState in SAML2 ECP responses","status":"NEW","created":"2026-09-15 09:35:34.000000000","updated":"2026-09-15 22:16:57.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":3,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"c9300925b029b2ad4a17c6eed4de8d5608a08be3","_number":1005691,"virtual_id_number":1005691,"owner":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"tag":"autogenerated:zuul:check","value":-1,"date":"2026-09-15 22:16:57.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"all":[{"value":2,"date":"2026-09-15 21:31:07.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-15 09:39:47.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-09-15 21:31:04.000000000","updated_by":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"reviewer":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"state":"REVIEWER"}],"messages":[{"id":"32ba147ae5e11de75cd5b6a005c0a59d5f1e4950","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:35:34.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"6b5c5cc6bdd73dd729b7c7e4e2627fb59699e009","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-15 09:39:47.000000000","message":"Patch Set 1: Verified-1\n\nThis change depends on a change that failed to merge.\n\nChange https://review.opendev.org/c/openstack/keystoneauth/+/1005690 is needed.","accounts_in_message":[],"_revision_number":1},{"id":"d780d6e227e390c72966a673f1dc99e1c28f4eeb","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:39:49.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased. Commit message was updated.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"74e85156c900c2457a85163de741eb71486028bf","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:44:09.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"01499250c7bd7e3ad3c905233434495165640b4f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-15 09:49:15.000000000","message":"Uploaded patch set 4: Commit message was updated.","accounts_in_message":[],"_revision_number":4},{"id":"bc58e1e7264f43372461c9750be47207cad5bda9","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-15 11:04:14.000000000","message":"Patch Set 4: Verified-1\n\n(1 comment)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/29ffd32d80e8464885096208f814d97d\n\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/3d7a0f54cb0f47459f943ac38ce28a11 : SUCCESS in 1h 05m 45s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/7eff28af50b74c6f94bde277a41e651a : FAILURE in 7m 41s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/97350c035fdd47cfb32031cfab701399 : SUCCESS in 6m 49s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/407ca8b44bfb466eb492e0dc62d70406 : SUCCESS in 8m 34s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/76418d847ddf4cf68d81bc0ea1b3c698 : SUCCESS in 9m 33s\n- openstack-tox-py315 https://zuul.opendev.org/t/openstack/build/b79c023741704c318ea72c73c243b4de : SUCCESS in 16m 15s (non-voting)\n- openstacksdk-functional-devstack-tips https://zuul.opendev.org/t/openstack/build/edf2e83754c4400f8a4872ebfa3f2209 : SUCCESS in 1h 08m 45s\n- osc-tox-py311-tips https://zuul.opendev.org/t/openstack/build/fa2226c8f5494b0e9e0dad5f973a084c : SUCCESS in 4m 20s\n- osc-tox-py314-tips https://zuul.opendev.org/t/openstack/build/f8de6df844d846f694b0ed99b86f1a99 : SUCCESS in 7m 37s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/460a90bacda54233807578fc83594c94 : SUCCESS in 8m 20s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/490826825240410080e2273672af7382 : SUCCESS in 4m 01s","accounts_in_message":[],"_revision_number":4},{"id":"15aa9a196e4dd2011a1cf955ead5c637b429e68d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-15 21:29:29.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"cb13164b76011a108cc3b36bca17e46154c302f9","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-15 21:30:51.000000000","message":"Patch Set 5: Verified-1\n\nThis change depends on a change that failed to merge.\n\nChange https://review.opendev.org/c/openstack/keystoneauth/+/1005690 is needed.","accounts_in_message":[],"_revision_number":5},{"id":"2934be2afe2ebe229d51982d5261bf2fac0b5579","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-15 21:31:04.000000000","message":"Patch Set 5: Code-Review+2","accounts_in_message":[],"_revision_number":5},{"id":"365bce409259af5335b89659e53f177edac8e209","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2026-09-15 21:31:07.000000000","message":"Patch Set 6: Patch Set 5 was rebased\n\nCopied Votes:\n* Code-Review+2 (copy condition: \"**changekind:TRIVIAL_REBASE** OR is:MIN\")\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":6},{"id":"c9300925b029b2ad4a17c6eed4de8d5608a08be3","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-15 22:16:57.000000000","message":"Patch Set 6: Verified-1\n\n(2 comments)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/17584e7b2c514ab39900627cbafe342f\n\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/a505d6655fae40f3826ddc84638101ce : SUCCESS in 44m 16s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/632ea34b5d6548ee8ce226800a54f6a9 : FAILURE in 5m 43s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/97e3dc61ac6b446d96f619824d4b1fbe : SUCCESS in 7m 19s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/31fadbe947bc4162bb41c80755d0d727 : SUCCESS in 6m 05s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/304625efee7b4c1ab7ebc2d60bd4a0f3 : SUCCESS in 5m 26s\n- openstack-tox-py315 https://zuul.opendev.org/t/openstack/build/cab1820c90ec46da87aedde1e76c0d18 : SUCCESS in 16m 34s (non-voting)\n- openstacksdk-functional-devstack-tips https://zuul.opendev.org/t/openstack/build/7dba2d912dad4ff19395a99acf48b406 : SUCCESS in 28m 54s\n- osc-tox-py311-tips https://zuul.opendev.org/t/openstack/build/570278d44a7142f5bceed1a041a1879a : SUCCESS in 5m 21s\n- osc-tox-py314-tips https://zuul.opendev.org/t/openstack/build/bcdb58429afd420680119e078e730f55 : SUCCESS in 6m 11s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/221d353bb9814bf18fe9f445eb7305c0 : SUCCESS in 8m 37s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/f6ccca55e8774ee8909ddd2b9bda5b27 : SUCCESS in 5m 06s","accounts_in_message":[],"_revision_number":6}],"current_revision_number":6,"current_revision":"1c18a1db60ce95e0741fc516ce1b28112971e9e6","revisions":{"4e56fac2aaf32187e993da3b31c826dea617316d":{"kind":"REWORK","_number":1,"created":"2026-09-15 09:35:34.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/91/1005691/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/91/1005691/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/1"}}},"commit":{"parents":[{"commit":"a90e877eaf5e1417619d0b51f5b046c8ba7e244d","subject":"Resolve relative ACS redirect Location in SAML2 ECP","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/a90e877eaf5e1417619d0b51f5b046c8ba7e244d"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:35:29.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:35:29.000000000","tz":120},"subject":"Handle optional RelayState in SAML2 ECP responses","message":"Handle optional RelayState in SAML2 ECP responses\n\nThe ECP profile treats RelayState as optional, but the client always\nindexed the first match and overwrote the first SOAP header child via\npositional assignment. Skip relay handling when the SP omits RelayState\nand replace any ecp:Response element explicitly when it is present.\n\nDepends-On: Ic4efdfb19e8cc6956d55d27cedf52735e161b3cf\nDepends-On: I0b0612290ab415eef2b96b51fa16f6e3bd766530\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: I96b14110c0786d92b87df45a8407699ef733a130\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/4e56fac2aaf32187e993da3b31c826dea617316d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/4e56fac2aaf32187e993da3b31c826dea617316d"}]},"branch":"refs/heads/master"},"5910086e708d0971abe208cf6e65b691369bda28":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":2,"created":"2026-09-15 09:39:49.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/91/1005691/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/91/1005691/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/2"}}},"commit":{"parents":[{"commit":"468a0490af3e88d19f1b9f63deba0d55831c490f","subject":"Resolve relative ACS redirect Location in SAML2 ECP","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/468a0490af3e88d19f1b9f63deba0d55831c490f"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:35:29.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:39:44.000000000","tz":120},"subject":"Handle optional RelayState in SAML2 ECP responses","message":"Handle optional RelayState in SAML2 ECP responses\n\nThe ECP profile treats RelayState as optional, but the client always\nindexed the first match and overwrote the first SOAP header child via\npositional assignment. Skip relay handling when the SP omits RelayState\nand replace any ecp:Response element explicitly when it is present.\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: I96b14110c0786d92b87df45a8407699ef733a130\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/5910086e708d0971abe208cf6e65b691369bda28"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/5910086e708d0971abe208cf6e65b691369bda28"}]},"branch":"refs/heads/master"},"e14b7f3eb9aba08c9cccc137eba0f867b3002414":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-09-15 09:44:09.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/91/1005691/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/91/1005691/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/3"}}},"commit":{"parents":[{"commit":"ad6a764082c11f36edc5fb47357ab3b6ea64aeb5","subject":"Resolve relative ACS redirect Location in SAML2 ECP","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/ad6a764082c11f36edc5fb47357ab3b6ea64aeb5"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:35:29.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:43:48.000000000","tz":120},"subject":"Handle optional RelayState in SAML2 ECP responses","message":"Handle optional RelayState in SAML2 ECP responses\n\nThe ECP profile treats RelayState as optional, but the client always\nindexed the first match and overwrote the first SOAP header child via\npositional assignment. Skip relay handling when the SP omits RelayState\nand replace any ecp:Response element explicitly when it is present.\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: I96b14110c0786d92b87df45a8407699ef733a130\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/e14b7f3eb9aba08c9cccc137eba0f867b3002414"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/e14b7f3eb9aba08c9cccc137eba0f867b3002414"}]},"branch":"refs/heads/master"},"b469837ccece8a53ef37d8915ebd471ba6c5d74a":{"kind":"NO_CODE_CHANGE","_number":4,"created":"2026-09-15 09:49:15.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/91/1005691/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/91/1005691/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/4"}}},"commit":{"parents":[{"commit":"6e4faeab42a7d8a5f447cfc2fafba816dda79136","subject":"Resolve relative ACS redirect Location in SAML2 ECP","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/6e4faeab42a7d8a5f447cfc2fafba816dda79136"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:35:29.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:49:00.000000000","tz":120},"subject":"Handle optional RelayState in SAML2 ECP responses","message":"Handle optional RelayState in SAML2 ECP responses\n\nThe ECP profile treats RelayState as optional, but the client always\nindexed the first match and overwrote the first SOAP header child via\npositional assignment. Skip relay handling when the SP omits RelayState\nand replace any ecp:Response element explicitly when it is present.\n\nDepends-On: I0b0612290ab415eef2b96b51fa16f6e3bd766530\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: I96b14110c0786d92b87df45a8407699ef733a130\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/b469837ccece8a53ef37d8915ebd471ba6c5d74a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/b469837ccece8a53ef37d8915ebd471ba6c5d74a"}]},"branch":"refs/heads/master"},"0814ba18ab54cdb1a728f5702a34c86ee2c6c287":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-09-15 21:29:29.000000000","uploader":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"ref":"refs/changes/91/1005691/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/91/1005691/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/5"}}},"commit":{"parents":[{"commit":"0b5a42e470e3472846a97ff355f4610fa0801de1","subject":"Resolve relative ACS redirect Location in SAML2 ECP","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/0b5a42e470e3472846a97ff355f4610fa0801de1"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:35:29.000000000","tz":120},"committer":{"name":"Stephen Finucane","email":"stephenfin@redhat.com","date":"2026-09-15 21:29:18.000000000","tz":60},"subject":"Handle optional RelayState in SAML2 ECP responses","message":"Handle optional RelayState in SAML2 ECP responses\n\nThe ECP profile treats RelayState as optional, but the client always\nindexed the first match and overwrote the first SOAP header child via\npositional assignment. Skip relay handling when the SP omits RelayState\nand replace any ecp:Response element explicitly when it is present.\n\nDepends-On: I0b0612290ab415eef2b96b51fa16f6e3bd766530\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: I96b14110c0786d92b87df45a8407699ef733a130\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/0814ba18ab54cdb1a728f5702a34c86ee2c6c287"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/0814ba18ab54cdb1a728f5702a34c86ee2c6c287"}]},"branch":"refs/heads/master"},"1c18a1db60ce95e0741fc516ce1b28112971e9e6":{"kind":"NO_CHANGE","_number":6,"created":"2026-09-15 21:31:07.000000000","uploader":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"ref":"refs/changes/91/1005691/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystoneauth","ref":"refs/changes/91/1005691/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystoneauth refs/changes/91/1005691/6"}}},"commit":{"parents":[{"commit":"be8a738fb4cfd133803377504534c40b8387c247","subject":"Resolve relative ACS redirect Location in SAML2 ECP","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/be8a738fb4cfd133803377504534c40b8387c247"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-09-15 09:35:29.000000000","tz":120},"committer":{"name":"Stephen Finucane","email":"stephenfin@redhat.com","date":"2026-09-15 21:31:07.000000000","tz":0},"subject":"Handle optional RelayState in SAML2 ECP responses","message":"Handle optional RelayState in SAML2 ECP responses\n\nThe ECP profile treats RelayState as optional, but the client always\nindexed the first match and overwrote the first SOAP header child via\npositional assignment. Skip relay handling when the SP omits RelayState\nand replace any ecp:Response element explicitly when it is present.\n\nDepends-On: I0b0612290ab415eef2b96b51fa16f6e3bd766530\n\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: I96b14110c0786d92b87df45a8407699ef733a130\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/1c18a1db60ce95e0741fc516ce1b28112971e9e6"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystoneauth/commit/1c18a1db60ce95e0741fc516ce1b28112971e9e6"}]},"branch":"refs/heads/master","description":"Rebase","conflicts":{"base":"0b5a42e470e3472846a97ff355f4610fa0801de1","ours":"0814ba18ab54cdb1a728f5702a34c86ee2c6c287","theirs":"be8a738fb4cfd133803377504534c40b8387c247","merge_strategy":"recursive","contains_conflicts":false}}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"}},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
