)]}'
{"id":"openstack%2Fkeystonemiddleware~947681","triplet_id":"openstack%2Fkeystonemiddleware~master~I3bb4d50683e7e1c71867ce650d119ccade4694a2","project":"openstack/keystonemiddleware","branch":"master","topic":"appcred-validation-no-catalog","attention_set":{"25468":{"account":{"_account_id":25468,"name":"Michel Nederlof","email":"michel@nederlof.info","username":"pellucid"},"last_update":"2026-08-12 15:52:15.000000000","reason":"\u003cGERRIT_ACCOUNT_5890\u003e replied on the change","reason_account":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"}}},"removed_from_attention_set":{},"hashtags":[],"change_id":"I3bb4d50683e7e1c71867ce650d119ccade4694a2","subject":"Fix Application Credentials with restricted access rules if there is no catalog requested.","status":"NEW","created":"2025-04-18 19:11:44.000000000","updated":"2026-08-12 15:52:15.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"2f55153e9a7b45c06b70b72b0c86fbb42868cf5c","_number":947681,"virtual_id_number":947681,"owner":{"_account_id":25468,"name":"Michel Nederlof","email":"michel@nederlof.info","username":"pellucid"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"tag":"autogenerated:zuul:check","value":1,"date":"2025-04-18 20:30:25.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"recommended":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"all":[{"value":1,"date":"2026-08-12 15:52:15.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2025-04-18 20:30:25.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-08-12 15:52:15.000000000","updated_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"reviewer":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"state":"REVIEWER"}],"messages":[{"id":"9f5a479bd6511c9bb0dd3ad93dd449217b90d768","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25468,"name":"Michel Nederlof","email":"michel@nederlof.info","username":"pellucid"},"date":"2025-04-18 19:11:44.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"51d638c327560a6299b46ef1cb8a80a6eae21da1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25468,"name":"Michel Nederlof","email":"michel@nederlof.info","username":"pellucid"},"date":"2025-04-18 19:12:59.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"ec179cf4164c48fff06e54c6833dfb8f2ef0bbf5","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-04-18 20:30:25.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/5d92c65249724c4f9eb3db6290baf0e7\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c1159fc5e5c040bb97b3d1f2154ffc33 : SUCCESS in 6m 13s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5ea4b776511f4cc9a60b1410543db1e3 : SUCCESS in 4m 06s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/f11fea0031dc4a5bad857c9f1735038b : SUCCESS in 2m 57s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/e5e6dcfbb890487ca5880d0685f229ab : SUCCESS in 3m 00s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/d438ac372ff54fdea503f7cdb6f4a161 : SUCCESS in 3m 44s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/5c4d6ac449d7462ebad51f505bf37964 : SUCCESS in 6m 50s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/fff4917765e54b3abd0cb91c87f1c940 : SUCCESS in 1h 17m 04s","accounts_in_message":[],"_revision_number":2},{"id":"2f55153e9a7b45c06b70b72b0c86fbb42868cf5c","author":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"},"date":"2026-08-12 15:52:15.000000000","message":"Patch Set 2: Code-Review+1","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"abd0219e2e98c156979aa4102db17d1a37cf0a16","revisions":{"5c177595f56ee04f9a2e0758e3cfaa6f60b5aaf5":{"kind":"REWORK","_number":1,"created":"2025-04-18 19:11:44.000000000","uploader":{"_account_id":25468,"name":"Michel Nederlof","email":"michel@nederlof.info","username":"pellucid"},"ref":"refs/changes/81/947681/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystonemiddleware","ref":"refs/changes/81/947681/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/1"}}},"commit":{"parents":[{"commit":"310b25afd09a52c8cd043d370ce9e5515caba29b","subject":"Merge \"Switch from python-memcache to pymemcache\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/310b25afd09a52c8cd043d370ce9e5515caba29b"}]}],"author":{"name":"Michel Nederlof","email":"mnederlof@cloudvps.com","date":"2025-04-18 19:11:34.000000000","tz":0},"committer":{"name":"Michel Nederlof","email":"mnederlof@cloudvps.com","date":"2025-04-18 19:11:43.000000000","tz":0},"subject":"Fix Application Credentials with restricted access rules if there is no catalog requested.","message":"Fix Application Credentials with restricted access rules if there is no catalog requested.\n\nWithout service catalog it is not possible to validate if the service_type has been configured correctly.\n\nFor example in swift it is recommended to set  `include_service_catalog` to `False` for the authtoken validation, as this saves in rendering time and data transfer time.\n\nAlso, i would opt that this check is merely for the operator to see if the configuration of the service_type is done correctly and it has little added functionality for the end-user.\n\nThe other result of setting `include_service_catalog` to `True` is that it will store the entire catalog in the request headers. When those are used in subsequent backend requests it will trigger a `Header Too Long` error if the catalog is large..\n\nChange-Id: I3bb4d50683e7e1c71867ce650d119ccade4694a2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/5c177595f56ee04f9a2e0758e3cfaa6f60b5aaf5"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/5c177595f56ee04f9a2e0758e3cfaa6f60b5aaf5"}]},"branch":"refs/heads/master"},"abd0219e2e98c156979aa4102db17d1a37cf0a16":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2025-04-18 19:12:59.000000000","uploader":{"_account_id":25468,"name":"Michel Nederlof","email":"michel@nederlof.info","username":"pellucid"},"ref":"refs/changes/81/947681/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystonemiddleware","ref":"refs/changes/81/947681/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystonemiddleware refs/changes/81/947681/2"}}},"commit":{"parents":[{"commit":"310b25afd09a52c8cd043d370ce9e5515caba29b","subject":"Merge \"Switch from python-memcache to pymemcache\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/310b25afd09a52c8cd043d370ce9e5515caba29b"}]}],"author":{"name":"Michel Nederlof","email":"mnederlof@cloudvps.com","date":"2025-04-18 19:11:34.000000000","tz":0},"committer":{"name":"Michel Nederlof","email":"mnederlof@cloudvps.com","date":"2025-04-18 19:12:32.000000000","tz":0},"subject":"Fix Application Credentials with restricted access rules if there is no catalog requested.","message":"Fix Application Credentials with restricted access rules if there is no catalog requested.\n\nWithout service catalog it is not possible to validate if the service_type has been configured correctly.\n\nFor example in swift it is recommended to set  `include_service_catalog` to `False` for the authtoken validation, as this saves in rendering time and data transfer time.\n\nAlso, i would opt that this check is merely for the operator to see if the configuration of the service_type is done correctly and it has little added functionality for the end-user.\n\nThe other result of setting `include_service_catalog` to `True` is that it will store the entire catalog in the request headers. When those are used in subsequent backend requests it will trigger a `Header Too Long` error if the catalog is large..\n\nRelated-bug: #1657390\n\nChange-Id: I3bb4d50683e7e1c71867ce650d119ccade4694a2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/abd0219e2e98c156979aa4102db17d1a37cf0a16"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/abd0219e2e98c156979aa4102db17d1a37cf0a16"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":5890,"name":"Doug Goldstein","email":"cardoe@cardoe.com","username":"cardoe"}},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
