)]}'
{"id":"openstack%2Fkeystonemiddleware~973496","triplet_id":"openstack%2Fkeystonemiddleware~stable%2F2025.1~Idd4fe1d17a25b3064b31f454d9830242f345e018","project":"openstack/keystonemiddleware","branch":"stable/2025.1","attention_set":{},"removed_from_attention_set":{"27900":{"account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"last_update":"2026-01-16 15:27:19.000000000","reason":"Change was submitted"},"5263":{"account":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"last_update":"2026-01-16 15:27:19.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"Idd4fe1d17a25b3064b31f454d9830242f345e018","subject":"Fix privilege escalation via spoofed identity headers","status":"MERGED","created":"2026-01-15 15:05:31.000000000","updated":"2026-01-16 15:28:39.000000000","submitted":"2026-01-16 15:27:19.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"973496","meta_rev_id":"d05a5bfa6f34fef0a0f2d803f192c57081d3dd61","_number":973496,"virtual_id_number":973496,"owner":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-01-16 15:27:19.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"all":[{"value":2,"date":"2026-01-16 14:20:21.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":2,"date":"2026-01-15 19:43:55.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"all":[{"value":1,"date":"2026-01-16 14:20:21.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-01-15 15:05:31.000000000","updated_by":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"CC"},{"updated":"2026-01-15 15:33:23.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"state":"REVIEWER"},{"updated":"2026-01-15 16:57:57.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-01-16 14:20:21.000000000","updated_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"}],"messages":[{"id":"c613c667919bf1f185275d910f5a54f0fb207719","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"date":"2026-01-15 15:05:31.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"14d664d06571223fab3e0684713a9cf36ddf4b56","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-01-15 15:33:23.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"38cd8d2fcd64538ee7b57a879e352a2b84aeb4e5","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-01-15 16:57:57.000000000","message":"Patch Set 1: Verified-1\n\n(1 comment)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/98801805515547faadf42f305e35f6d5\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/fc63a90b22bd4c9db78934544fd7db6b : SUCCESS in 3m 44s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/7f684c637628485e833f12019932fc03 : FAILURE in 1m 48s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/b806f2b8170e4fbca16a681a8cb3fbd5 : SUCCESS in 6m 41s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/4254fb6f10944550bca0ef530e52a472 : SUCCESS in 4m 06s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/633967b854ca4c9999b59e2a3083b9c1 : SUCCESS in 4m 31s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/b8005dae7fc941b8a6f8de1b5d24bebf : SUCCESS in 1h 47m 30s","accounts_in_message":[],"_revision_number":1},{"id":"668ca3c5b510c27b478115ba6c0e2f8b6901cb28","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-01-15 17:33:19.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified-1\n","accounts_in_message":[],"_revision_number":2},{"id":"937ed4f05cec7ad6e8028a87b1569cba82c61831","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-01-15 19:31:21.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f052650e9af14c1fac529bdd246abf36\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/a9efc8e4dfbd4438a7252f341f1de3fd : SUCCESS in 5m 01s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/832a4dde9dd848918dba71758b9a5600 : SUCCESS in 4m 21s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/d4019aebe4f14738b873b6b73287d9a5 : SUCCESS in 3m 47s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/3dc1f7f24bde40478f7dd539d60f2d8c : SUCCESS in 4m 03s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d8ec98ae2a6e42e88ea61024dcde1b99 : SUCCESS in 6m 38s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/e6fc83b2ed314f2db816defbe92f4660 : SUCCESS in 1h 52m 14s","accounts_in_message":[],"_revision_number":2},{"id":"12e7d7e43a184cba35a696a86668062931b03b30","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-01-15 19:43:55.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"46fcf3a4187bbd92879997e66245a004ac496d17","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-01-16 14:20:21.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":2},{"id":"0435247aa8c82725ae57bb6adad4c1552130ea44","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-01-16 14:20:46.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"e1980e86b6fee46d6c8748a201149d90f244d151","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-01-16 15:27:19.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/a53446f3cb624b9cbb338956e3cacb10\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/220042e89fde400a90d9750c058af189 : SUCCESS in 3m 07s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/33b8c87a222340d696bedf71aac90724 : SUCCESS in 3m 01s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/232f6e9948c745389ac9cbd111891e30 : SUCCESS in 3m 04s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/429d46d4a8a24242b3c48b9351b368dc : SUCCESS in 5m 45s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/46bed0b779204c14b83979d443966a1a : SUCCESS in 59m 18s","accounts_in_message":[],"_revision_number":2},{"id":"022839355f334131ca9da31e0ea4689d57dff98a","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-01-16 15:27:19.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"d05a5bfa6f34fef0a0f2d803f192c57081d3dd61","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-01-16 15:28:39.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/c3602671cb474c72ac3abf9220818614\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a5456500560d4b79839b82116bf467d7 : SUCCESS in 56s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"9401c513219f86008d1df380a10d57464bb20b2d","revisions":{"2a2556ac8789f6409f93178f1bfaad9b59b29047":{"kind":"REWORK","_number":1,"created":"2026-01-15 15:05:31.000000000","uploader":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"ref":"refs/changes/96/973496/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystonemiddleware","ref":"refs/changes/96/973496/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/1"}}},"commit":{"parents":[{"commit":"2f02aed94b8622d9355db83be0dc8c4201129f6d","subject":"Update TOX_CONSTRAINTS_FILE for stable/2025.1","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/2f02aed94b8622d9355db83be0dc8c4201129f6d"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-01-08 13:46:19.000000000","tz":60},"committer":{"name":"Jeremy Stanley","email":"fungi@yuggoth.org","date":"2026-01-15 15:05:20.000000000","tz":0},"subject":"Fix privilege escalation via spoofed identity headers","message":"Fix privilege escalation via spoofed identity headers\n\nThe external_oauth2_token middleware did not sanitize incoming\nauthentication headers before processing OAuth 2.0 tokens. This\nallowed an attacker to send forged identity headers (e.g.,\nX-Is-Admin-Project, X-Roles, X-User-Id) that would not be cleared\nby the middleware, potentially enabling privilege escalation.\n\nThis fix adds a call to remove_auth_headers() at the start of\nrequest processing to sanitize all incoming identity headers,\nmatching the secure behavior of the main auth_token middleware.\n\nCloses-Bug: #2129018\nChange-Id: Idd4fe1d17a25b3064b31f454d9830242f345e018\n(cherry picked from commit b473c0ed1467b70c74c8a82cb4d15ccf8424b27b)\nSigned-off-by: Jeremy Stanley \u003cfungi@yuggoth.org\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/2a2556ac8789f6409f93178f1bfaad9b59b29047"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/2a2556ac8789f6409f93178f1bfaad9b59b29047"}]},"branch":"refs/heads/stable/2025.1"},"9401c513219f86008d1df380a10d57464bb20b2d":{"kind":"REWORK","_number":2,"created":"2026-01-15 17:33:19.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/96/973496/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystonemiddleware","ref":"refs/changes/96/973496/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystonemiddleware refs/changes/96/973496/2"}}},"commit":{"parents":[{"commit":"2f02aed94b8622d9355db83be0dc8c4201129f6d","subject":"Update TOX_CONSTRAINTS_FILE for stable/2025.1","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/2f02aed94b8622d9355db83be0dc8c4201129f6d"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-01-08 13:46:19.000000000","tz":60},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-01-15 17:33:13.000000000","tz":60},"subject":"Fix privilege escalation via spoofed identity headers","message":"Fix privilege escalation via spoofed identity headers\n\nThe external_oauth2_token middleware did not sanitize incoming\nauthentication headers before processing OAuth 2.0 tokens. This\nallowed an attacker to send forged identity headers (e.g.,\nX-Is-Admin-Project, X-Roles, X-User-Id) that would not be cleared\nby the middleware, potentially enabling privilege escalation.\n\nThis fix adds a call to remove_auth_headers() at the start of\nrequest processing to sanitize all incoming identity headers,\nmatching the secure behavior of the main auth_token middleware.\n\nCloses-Bug: #2129018\nChange-Id: Idd4fe1d17a25b3064b31f454d9830242f345e018\n(cherry picked from commit b473c0ed1467b70c74c8a82cb4d15ccf8424b27b)\nSigned-off-by: Jeremy Stanley \u003cfungi@yuggoth.org\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/9401c513219f86008d1df380a10d57464bb20b2d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystonemiddleware/commit/9401c513219f86008d1df380a10d57464bb20b2d"}]},"branch":"refs/heads/stable/2025.1"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
