)]}'
{"id":"openstack%2Fkeystone~1002301","triplet_id":"openstack%2Fkeystone~master~Ic8775eb0fdaa2330206023818ce18f76430fa45e","project":"openstack/keystone","branch":"master","attention_set":{},"removed_from_attention_set":{"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-08-25 19:23:29.000000000","reason":"\u003cGERRIT_ACCOUNT_14250\u003e replied on the change","reason_account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}}},"hashtags":["CVE-2026-80182","OSSA-2026-037"],"change_id":"Ic8775eb0fdaa2330206023818ce18f76430fa45e","subject":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints","status":"NEW","created":"2026-08-25 14:47:47.000000000","updated":"2026-08-26 10:21:03.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":18,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"bb0fd22d8773f9fe077b54431473f956c39894b5","_number":1002301,"virtual_id_number":1002301,"owner":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-08-25 21:02:19.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"CC":[{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-25 16:10:12.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-08-26 10:21:03.000000000","updated_by":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"reviewer":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"state":"CC"}],"messages":[{"id":"50c5c8c6c2df5be8487efef13f8e140742ef32a0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-08-25 14:47:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"ce7847c1dfef81079347b4b942cee48146ae4a37","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-25 16:10:12.000000000","message":"Patch Set 1: Verified-1\n\n(17 comments)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/abbffe725918487783a432ae29fedd5c\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/694d45a7cdbb48abade0d6813418c7e2 : SUCCESS in 11m 32s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/1b466ca0c87f4f63932afedda311dde5 : FAILURE in 3m 29s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/45321cf8a88c421ab83ae370d1d8b450 : SUCCESS in 8m 23s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/3a2f3359428942c299018754cb49c8ac : SUCCESS in 11m 59s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/8594352e725e465e88d183c45d9c53bd : SUCCESS in 15m 58s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/cd075e1eaf2a42cfb5eda78f67a8d150 : SUCCESS in 11m 40s\n- grenade https://zuul.opendev.org/t/openstack/build/7f7d8989e97c45a6a937565523d90571 : SUCCESS in 58m 04s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/9dfffcbf63634f6b87754224d1d195bc : SUCCESS in 1h 17m 50s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/cb5fa2f762d246328caa61c740c98418 : SUCCESS in 14m 22s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/a5602228b1ec4d72a821987575c337f7 : SUCCESS in 11m 53s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/6a9eeac6a4654677b64e4b415a26ba4c : SUCCESS in 49m 35s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/e3ac86d6e3a44f61a5a13d22a05ffe68 : FAILURE in 13m 35s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/9a0b0435c4c7496e9fa9d81a6fa2b7d5 : FAILURE in 20m 11s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/7acb88af30fd4990a4b728e70870f6b7 : SUCCESS in 42m 08s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/b7c21521d73148aca0a4cf5a1fef8f62 : SUCCESS in 58m 21s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/bbfc639ce0114656bd5f125ba651914d : SUCCESS in 39m 12s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/dfd3523b915e4e70b08eb7cdf8bc47d7 : SUCCESS in 51m 58s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/b3f8d8b683bf40e5a7311b6e05542228 : SUCCESS in 42m 07s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/273b99c493944a1fb70840fb3f2bfa5f : SUCCESS in 5m 56s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":1},{"id":"ad3dd6ba44efab968ff879df75362bc461dd1c5e","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-08-25 19:23:29.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"fd98736f078293efb08eff17f8e3742e8ec36bd1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-08-25 19:29:41.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"3c4c8c4d6c04234a5bf37ef6db0930b59afed82a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-25 21:02:19.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/80836f510fca44a3b6e9c25876b22a1c\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/769fbea4cb3d4c32b342d369d9bf7008 : SUCCESS in 14m 29s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/64e2cd93bb4c4fe9bff20883b3275550 : SUCCESS in 5m 04s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/2e9b9d85412443c9b23504bb863692bf : SUCCESS in 12m 02s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/83b686f5590847deb8f0ef63cdaa31f7 : SUCCESS in 8m 38s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/3fbfbfb839544528940b8137fbf5e1ae : SUCCESS in 19m 32s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/75523dc209ec4b09b9d204c671103deb : SUCCESS in 13m 14s\n- grenade https://zuul.opendev.org/t/openstack/build/27dbc0fad4b040d886ffd0df3d1e80c4 : SUCCESS in 37m 21s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/a6e1226f02374aec9148e73b5227f53f : SUCCESS in 1h 27m 18s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/c2edb2b58f624c1fb3971b1cd127516d : SUCCESS in 6m 15s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/2717fb08c14e4e709bc91eeb63fe8a52 : SUCCESS in 18m 15s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/5ed54ac7bddf42dd856038c8836aee63 : SUCCESS in 49m 29s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/be3b722ee4b649e9868182a4232e8daa : FAILURE in 18m 01s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/c29748ff828c47cfbd10fcdb17105f22 : FAILURE in 28m 50s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/8bfa828955514eaba9cc02fa7ff5c5cc : SUCCESS in 49m 23s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/d85f53701b494f4c92e7caa14fdebede : SUCCESS in 50m 58s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/9e1cea47b2bb44c5aacb9521c12871b7 : SUCCESS in 23m 05s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/f73a0b89db7d457e9e388346d4f16565 : SUCCESS in 54m 39s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/6babf81fbab147c385642539c035cbc3 : SUCCESS in 19m 49s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/a442bc2c23934265859c34be7cacdc12 : SUCCESS in 4m 24s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":2},{"id":"330decb3f36610a7bd88c965fc771d18ba88917f","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-25 21:12:17.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/9ea4a89dc89a4e24ab04f43ddf3283b5\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/1b8062d2756d445bb868fac2a345e11f : SUCCESS in 16m 52s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/32f3a9228fc74b21b59f145e180b962b : SUCCESS in 17m 58s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/dbfb687015424d92982edf1eaa1ba166 : SUCCESS in 16m 00s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"44441b33c0b125622361f67dc329cd411ab2f595","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"date":"2026-08-25 22:13:00.000000000","message":"Hashtags added: CVE-2026-80182, OSSA-2026-037","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"aeea08706020a1a66954256053689a361b04c2fd","revisions":{"eed696ba20f40571e2a3d430ddbe3c18aa91de7e":{"kind":"REWORK","_number":1,"created":"2026-08-25 14:47:47.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/01/1002301/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/01/1002301/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/01/1002301/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/01/1002301/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/01/1002301/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/01/1002301/1"}}},"commit":{"parents":[{"commit":"16afc813b7e6de727d8a91e065d7824b06e32925","subject":"Merge \"Abandon server-side paged search cursor when sizelimit is reached\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/16afc813b7e6de727d8a91e065d7824b06e32925"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-07-23 07:32:00.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-08-25 14:47:35.000000000","tz":120},"subject":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints","message":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints\n\n_check_application_credential() in trusts.py only recognized\n\u0027application_credential\u0027 in token.methods, so OAuth1 access-token-scoped\nand ec2credential-derived tokens were never blocked from creating,\nlisting, reading, or deleting trusts -- unlike application_credential,\nwhich has had this restriction since LP#2148477.\n\nTwo more endpoints that mint a new persistent grant had the same gap:\n\n- users.py\u0027s _block_delegated_token_app_creds (guarding application\n  credential and access-rule CRUD) only checked trust_id/access_token_id,\n  so ec2credential-scoped tokens could create, list, read, and delete\n  application credentials.\n- os_oauth1.py\u0027s AuthorizeResource.put (PUT /v3/OS-OAUTH1/authorize) only\n  checked is_delegated_auth (trust/oauth1) and application_credential, so\n  an ec2credential-scoped token could authorize OAuth1 request tokens.\n\nAll three are extended to the same primary-auth-method allowlist used in\ncredentials.py, users.py, and token.py: any token whose methods aren\u0027t\nentirely primary auth methods is rejected outright. Trust-scoped tokens\nare deliberately not blocked from trust operations on trust_id alone --\nthat\u0027s the trust redelegation feature working as designed (a trustee\ncreating a further, narrower trust from one they were delegated) and\ntrustee self-service reads of their own trusts. A trust-scoped token\nwhose underlying method is itself delegated (an EC2 credential\u0027s blob\ncan embed a trust_id, see keystone.api.credentials._assign_unique_id) is\nstill caught by the method check regardless of trust scoping.\napplication_credential keeps its existing, documented opt-in escape\nhatch for trust management\n(allow_insecure_application_credential_trust_escalation) and its\nunrestricted/restricted distinction for creating further application\ncredentials (_check_unrestricted_application_credential); OAuth1 and EC2\ncredentials have no such use case and are blocked unconditionally\neverywhere.\n\nThis also closes off the underlying role-escalation path in trust\ncreation: trust role validation checks the trustor\u0027s full role\nassignments, not the requesting token\u0027s own scoped roles, so a\nnarrowly-scoped oauth1/ec2 token could previously delegate roles it was\nnever itself authorized for. Blocking those token types from trust\ncreation removes the path to that gap without needing to touch the\nvalidation itself.\n\nNeither the app-cred nor the OAuth1-authorize gap is reachable on\ncurrent master, where a separate middleware change globally rejects any\ncaller token with \u0027ec2credential\u0027 in its methods before Flask routing --\nbut that change is not backported to stable branches, so both gaps are\nlive there. Fixed at the source regardless, so the guard doesn\u0027t depend\non an unrelated middleware check remaining in place.\n\nAn empty token.methods list (e.g. an ec2credential-derived token that\nlost its methods on a fernet cache-miss round-trip -- ec2credential has\nno bit in the method bitmask) is also treated as delegated at all three\ncall sites: _PRIMARY_AUTH_METHODS.issuperset([]) is True, so without this\nan empty list would otherwise be accepted as \u0027all primary\u0027.\n\nConsolidated the three independent _PRIMARY_AUTH_METHODS copies (this\npatch, LP#2158538, LP#2159643) into keystone.api._shared.delegation,\nper gtema\u0027s review comment #16 -- now that all three land together the\nNameError-avoidance reason for keeping them separate no longer applies.\nAlso replaced the hardcoded method list with an operator-extensible one\n([auth] additional_primary_auth_methods): a hardcoded allowlist blocks\nany third-party auth plugin (e.g. a site-specific SSO integration) from\nreauthenticating/managing its own trusts, app-creds, and OAuth1 tokens,\nsince it can never appear in a list only keystone maintainers can edit.\n\nCloses-Bug: #2153453\nChange-Id: Ic8775eb0fdaa2330206023818ce18f76430fa45e\nAssisted-by: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/eed696ba20f40571e2a3d430ddbe3c18aa91de7e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/eed696ba20f40571e2a3d430ddbe3c18aa91de7e"}]},"branch":"refs/heads/master"},"aeea08706020a1a66954256053689a361b04c2fd":{"kind":"REWORK","_number":2,"created":"2026-08-25 19:29:41.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/01/1002301/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/01/1002301/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/01/1002301/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/01/1002301/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/01/1002301/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/01/1002301/2"}}},"commit":{"parents":[{"commit":"16afc813b7e6de727d8a91e065d7824b06e32925","subject":"Merge \"Abandon server-side paged search cursor when sizelimit is reached\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/16afc813b7e6de727d8a91e065d7824b06e32925"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-07-23 07:32:00.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-08-25 19:28:52.000000000","tz":120},"subject":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints","message":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints\n\n_check_application_credential() in trusts.py only recognized\n\u0027application_credential\u0027 in token.methods, so OAuth1 access-token-scoped\nand ec2credential-derived tokens were never blocked from creating,\nlisting, reading, or deleting trusts -- unlike application_credential,\nwhich has had this restriction since LP#2148477.\n\nTwo more endpoints that mint a new persistent grant had the same gap:\n\n- users.py\u0027s _block_delegated_token_app_creds (guarding application\n  credential and access-rule CRUD) only checked trust_id/access_token_id,\n  so ec2credential-scoped tokens could create, list, read, and delete\n  application credentials.\n- os_oauth1.py\u0027s AuthorizeResource.put (PUT /v3/OS-OAUTH1/authorize) only\n  checked is_delegated_auth (trust/oauth1) and application_credential, so\n  an ec2credential-scoped token could authorize OAuth1 request tokens.\n\nAll three are extended to the same primary-auth-method allowlist used in\ncredentials.py, users.py, and token.py: any token whose methods aren\u0027t\nentirely primary auth methods is rejected outright. Trust-scoped tokens\nare deliberately not blocked from trust operations on trust_id alone --\nthat\u0027s the trust redelegation feature working as designed (a trustee\ncreating a further, narrower trust from one they were delegated) and\ntrustee self-service reads of their own trusts. A trust-scoped token\nwhose underlying method is itself delegated (an EC2 credential\u0027s blob\ncan embed a trust_id, see keystone.api.credentials._assign_unique_id) is\nstill caught by the method check regardless of trust scoping.\napplication_credential keeps its existing, documented opt-in escape\nhatch for trust management\n(allow_insecure_application_credential_trust_escalation) and its\nunrestricted/restricted distinction for creating further application\ncredentials (_check_unrestricted_application_credential); OAuth1 and EC2\ncredentials have no such use case and are blocked unconditionally\neverywhere.\n\nThis also closes off the underlying role-escalation path in trust\ncreation: trust role validation checks the trustor\u0027s full role\nassignments, not the requesting token\u0027s own scoped roles, so a\nnarrowly-scoped oauth1/ec2 token could previously delegate roles it was\nnever itself authorized for. Blocking those token types from trust\ncreation removes the path to that gap without needing to touch the\nvalidation itself.\n\nNeither the app-cred nor the OAuth1-authorize gap is reachable on\ncurrent master, where a separate middleware change globally rejects any\ncaller token with \u0027ec2credential\u0027 in its methods before Flask routing --\nbut that change is not backported to stable branches, so both gaps are\nlive there. Fixed at the source regardless, so the guard doesn\u0027t depend\non an unrelated middleware check remaining in place.\n\nAn empty token.methods list (e.g. an ec2credential-derived token that\nlost its methods on a fernet cache-miss round-trip -- ec2credential has\nno bit in the method bitmask) is also treated as delegated at all three\ncall sites: _PRIMARY_AUTH_METHODS.issuperset([]) is True, so without this\nan empty list would otherwise be accepted as \u0027all primary\u0027.\n\nConsolidated the three independent _PRIMARY_AUTH_METHODS copies (this\npatch, LP#2158538, LP#2159643) into keystone.api._shared.delegation,\nper gtema\u0027s review comment #16 -- now that all three land together the\nNameError-avoidance reason for keeping them separate no longer applies.\nAlso replaced the hardcoded method list with an operator-extensible one\n([auth] additional_primary_auth_methods): a hardcoded allowlist blocks\nany third-party auth plugin (e.g. a site-specific SSO integration) from\nreauthenticating/managing its own trusts, app-creds, and OAuth1 tokens,\nsince it can never appear in a list only keystone maintainers can edit.\n\nCloses-Bug: #2153453\nChange-Id: Ic8775eb0fdaa2330206023818ce18f76430fa45e\nAssisted-by: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/aeea08706020a1a66954256053689a361b04c2fd"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/aeea08706020a1a66954256053689a361b04c2fd"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
