)]}'
{"id":"openstack%2Fkeystone~1002303","triplet_id":"openstack%2Fkeystone~stable%2F2026.1~Ic8775eb0fdaa2330206023818ce18f76430fa45e","project":"openstack/keystone","branch":"stable/2026.1","attention_set":{"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-08-25 17:01:35.000000000","reason":"A robot voted negatively on a label"}},"removed_from_attention_set":{},"hashtags":["CVE-2026-80182","OSSA-2026-037"],"change_id":"Ic8775eb0fdaa2330206023818ce18f76430fa45e","subject":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints","status":"NEW","created":"2026-08-25 14:49:42.000000000","updated":"2026-08-26 21:39:12.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":18,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"5a9baf0024bb1283f97a17dae7fc634663a72b4a","_number":1002303,"virtual_id_number":1002303,"owner":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-08-26 21:39:12.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"CC":[{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-25 17:01:35.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-08-26 19:49:32.000000000","updated_by":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"reviewer":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"state":"CC"}],"messages":[{"id":"d681e42259f19f125c272875fa6d9d02dfdbb82d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-08-25 14:49:42.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"e31d4ac564141352f20eac40d667f4d4b36e44e2","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-25 17:01:35.000000000","message":"Patch Set 1: Verified-1\n\n(17 comments)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/8c92153267514573a9c6d27e9b9faad9\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/937881d15c294e1f9b23ca5396fd797b : SUCCESS in 13m 55s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a23951d2f9d948e79d7bf4e8b5df8618 : FAILURE in 3m 30s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/ca807151686042ccba6b1bee03c694ea : SUCCESS in 14m 01s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/8299a88758d54750a2b045c1b2412044 : SUCCESS in 11m 23s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/b78414085b2f41b88b3728fded042633 : SUCCESS in 11m 08s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/11935f0cea474446865a04b3fdd0ef1d : SUCCESS in 14m 13s\n- grenade https://zuul.opendev.org/t/openstack/build/b347343a3fe64c20962c419d530ffece : SUCCESS in 37m 05s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/a3b08ae8381c41839df76c2b0bef7394 : SUCCESS in 2h 05m 54s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/c5620a217c824574afcbfe47f496c35b : SUCCESS in 5m 31s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/4b084db78b7943a39b8f847477dc7862 : SUCCESS in 19m 52s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/c53f6d0f82804effb6fae7b8babaa9b6 : SUCCESS in 32m 09s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/50f614bbe33f494bbe2a818580a53399 : FAILURE in 7m 52s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/36c5a2f2ec4545bc9d60a3d40c7cf49b : FAILURE in 16m 20s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/06398f19e48f4384898fd1696f20b767 : SUCCESS in 24m 35s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/f4cd6a411ded4ad6a2041c4850d888d6 : SUCCESS in 24m 20s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/8eeb8ebcfd724f3799c58407e0e421b3 : SUCCESS in 42m 32s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/5d1175f050604b1f80bda50257a366b0 : SUCCESS in 59m 07s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/6db5ad2418a24c82bb4b3313ed01b377 : FAILURE in 15m 46s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/825d078b6d98424ba52a89349f8bcf80 : SUCCESS in 4m 49s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":1},{"id":"66c470decf6548a09c8ee587597a46b16f0204ac","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"date":"2026-08-25 22:13:00.000000000","message":"Hashtags added: CVE-2026-80182, OSSA-2026-037","accounts_in_message":[],"_revision_number":1},{"id":"92459d188fe118fbc6b5820fc73c0742da6a5984","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-08-25 22:28:25.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"8a7afdd23a2de408fc740ffa11a31ab88cd6552b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-26 00:35:37.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/9825498a04964e678a785f570d3a988c\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/4eeb4e1acaa4466c90c73bd786a89421 : SUCCESS in 17m 32s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/135705deafd047d1ba83db1b9a9b3369 : SUCCESS in 3m 39s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/5a2aff5560b541fa9a4589a5a4c25d8a : SUCCESS in 8m 14s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/f7672a47cd594dc68810c9d8a921c0dc : SUCCESS in 9m 25s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/4ff2456ccc694cb0ac2b39c94ba4f9b2 : SUCCESS in 9m 32s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/16c06b7c431340e2abd8dd42a34f62a8 : SUCCESS in 10m 56s\n- grenade https://zuul.opendev.org/t/openstack/build/841606dec75745bd8c04b7f7bd8f9811 : SUCCESS in 36m 21s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/83b82ba79dc9406887858850578c4324 : SUCCESS in 2h 01m 04s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/4f6e72164e2a4ff3971433a6f1061359 : SUCCESS in 12m 41s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/c7acfe96527a41cab51f139d550e1078 : SUCCESS in 18m 09s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/859c82703a454e4ab38062b6a0bb3a5d : SUCCESS in 29m 39s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/ed9e84d2f7b84422aac7d5c581c98485 : FAILURE in 17m 01s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/e5abe0d4d91542389c3c60714be21bb2 : FAILURE in 28m 18s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/1ecacd70995e43648949373410fbb271 : SUCCESS in 19m 28s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/9956a27ca8a54561b08846e123402dae : SUCCESS in 37m 39s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/77f593b496e34eab9064bcf7a1119c15 : SUCCESS in 34m 58s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/89d20774810c4585b8b9035f23331c7a : SUCCESS in 54m 32s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/771396a2affb48ce8b433a2be4b56df4 : FAILURE in 14m 52s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/8d94032bd6264cdfb791419f31c7df86 : SUCCESS in 7m 50s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":2},{"id":"d2001aa94437e17a1b3d5eec7fa02d7bf007e1c9","author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"date":"2026-08-26 19:49:32.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"5a9baf0024bb1283f97a17dae7fc634663a72b4a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-26 21:39:12.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/dcef4047d763478d872bd4e0fbba29d1\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/44a7cffa0107420a9bfe39966f511046 : SUCCESS in 12m 08s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/fb472e2e98a945b881f7692da1344f5e : SUCCESS in 3m 15s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/5a84bf2282c14119ba864dcb7a2c8e8d : SUCCESS in 7m 37s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/0010abcdfb9c40f79ec8ce9ccf436b50 : SUCCESS in 11m 20s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/54935774f15a43b6b451997d8077a776 : SUCCESS in 16m 08s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/2ed92a786edc47f895ae8adb7166194c : SUCCESS in 14m 01s\n- grenade https://zuul.opendev.org/t/openstack/build/4268fc3c9bc74b74b2690938c5205736 : SUCCESS in 59m 51s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/304b7c3bf84a4049b052e121f4d880c8 : SUCCESS in 1h 43m 58s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/8f2acad63dc447e69a7b453f09202542 : SUCCESS in 6m 29s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/3776044964424fae87990faececaf607 : SUCCESS in 13m 05s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/40ef1fe20bb242d6a8a70a8d7cf96e7f : SUCCESS in 30m 27s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/2505534790234ca0a9fddc956d906905 : FAILURE in 8m 18s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/0e2eb44ad83c4be9a0730139847d5a24 : FAILURE in 29m 59s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/73507b17679448b682093c56aa3b4864 : SUCCESS in 26m 21s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/11af09ee19a64e57aecd2bedd605a89f : SUCCESS in 14m 33s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/6b119cea5b964c49845c69e440050720 : SUCCESS in 39m 30s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/b800f5b70b5340309b30aaee2434ce27 : SUCCESS in 1h 13m 38s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/08c56b6e71b442c58ee919836e4b6207 : SUCCESS in 18m 24s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/9333b14a8da2415b8b65c7b27896c966 : SUCCESS in 3m 44s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"54c5a5f11e7e14c2fcc9f81568bcf471f71013fe","revisions":{"695056d21ff317e7ef6d4687b1d0ab2cafd38ceb":{"kind":"REWORK","_number":1,"created":"2026-08-25 14:49:42.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/03/1002303/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/03/1002303/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/1002303/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/1002303/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/1002303/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/03/1002303/1"}}},"commit":{"parents":[{"commit":"7b9f39226744b8db50a6d702cc5f715fc9c17f37","subject":"Merge \"Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)\" into stable/2026.1","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b9f39226744b8db50a6d702cc5f715fc9c17f37"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-07-23 07:32:00.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-08-25 14:48:06.000000000","tz":120},"subject":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints","message":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints\n\n_check_application_credential() in trusts.py only recognized\n\u0027application_credential\u0027 in token.methods, so OAuth1 access-token-scoped\nand ec2credential-derived tokens were never blocked from creating,\nlisting, reading, or deleting trusts -- unlike application_credential,\nwhich has had this restriction since LP#2148477.\n\nTwo more endpoints that mint a new persistent grant had the same gap:\n\n- users.py\u0027s _block_delegated_token_app_creds (guarding application\n  credential and access-rule CRUD) only checked trust_id/access_token_id,\n  so ec2credential-scoped tokens could create, list, read, and delete\n  application credentials.\n- os_oauth1.py\u0027s AuthorizeResource.put (PUT /v3/OS-OAUTH1/authorize) only\n  checked is_delegated_auth (trust/oauth1) and application_credential, so\n  an ec2credential-scoped token could authorize OAuth1 request tokens.\n\nAll three are extended to the same primary-auth-method allowlist used in\ncredentials.py, users.py, and token.py: any token whose methods aren\u0027t\nentirely primary auth methods is rejected outright. Trust-scoped tokens\nare deliberately not blocked from trust operations on trust_id alone --\nthat\u0027s the trust redelegation feature working as designed (a trustee\ncreating a further, narrower trust from one they were delegated) and\ntrustee self-service reads of their own trusts. A trust-scoped token\nwhose underlying method is itself delegated (an EC2 credential\u0027s blob\ncan embed a trust_id, see keystone.api.credentials._assign_unique_id) is\nstill caught by the method check regardless of trust scoping.\napplication_credential keeps its existing, documented opt-in escape\nhatch for trust management\n(allow_insecure_application_credential_trust_escalation) and its\nunrestricted/restricted distinction for creating further application\ncredentials (_check_unrestricted_application_credential); OAuth1 and EC2\ncredentials have no such use case and are blocked unconditionally\neverywhere.\n\nThis also closes off the underlying role-escalation path in trust\ncreation: trust role validation checks the trustor\u0027s full role\nassignments, not the requesting token\u0027s own scoped roles, so a\nnarrowly-scoped oauth1/ec2 token could previously delegate roles it was\nnever itself authorized for. Blocking those token types from trust\ncreation removes the path to that gap without needing to touch the\nvalidation itself.\n\nNeither the app-cred nor the OAuth1-authorize gap is reachable on\ncurrent master, where a separate middleware change globally rejects any\ncaller token with \u0027ec2credential\u0027 in its methods before Flask routing --\nbut that change is not backported to stable branches, so both gaps are\nlive there. Fixed at the source regardless, so the guard doesn\u0027t depend\non an unrelated middleware check remaining in place.\n\nAn empty token.methods list (e.g. an ec2credential-derived token that\nlost its methods on a fernet cache-miss round-trip -- ec2credential has\nno bit in the method bitmask) is also treated as delegated at all three\ncall sites: _PRIMARY_AUTH_METHODS.issuperset([]) is True, so without this\nan empty list would otherwise be accepted as \u0027all primary\u0027.\n\nConsolidated the three independent _PRIMARY_AUTH_METHODS copies (this\npatch, LP#2158538, LP#2159643) into keystone.api._shared.delegation,\nper gtema\u0027s review comment #16 -- now that all three land together the\nNameError-avoidance reason for keeping them separate no longer applies.\nAlso replaced the hardcoded method list with an operator-extensible one\n([auth] additional_primary_auth_methods): a hardcoded allowlist blocks\nany third-party auth plugin (e.g. a site-specific SSO integration) from\nreauthenticating/managing its own trusts, app-creds, and OAuth1 tokens,\nsince it can never appear in a list only keystone maintainers can edit.\n\nCloses-Bug: #2153453\nChange-Id: Ic8775eb0fdaa2330206023818ce18f76430fa45e\nAssisted-by: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/695056d21ff317e7ef6d4687b1d0ab2cafd38ceb"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/695056d21ff317e7ef6d4687b1d0ab2cafd38ceb"}]},"branch":"refs/heads/stable/2026.1"},"54c5a5f11e7e14c2fcc9f81568bcf471f71013fe":{"kind":"REWORK","_number":2,"created":"2026-08-25 22:28:25.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/03/1002303/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/03/1002303/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/1002303/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/1002303/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/1002303/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/03/1002303/2"}}},"commit":{"parents":[{"commit":"7b9f39226744b8db50a6d702cc5f715fc9c17f37","subject":"Merge \"Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)\" into stable/2026.1","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b9f39226744b8db50a6d702cc5f715fc9c17f37"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-07-23 07:32:00.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-08-25 22:26:12.000000000","tz":120},"subject":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints","message":"trusts, oauth1, app-creds: reject delegated tokens across all endpoints\n\n_check_application_credential() in trusts.py only recognized\n\u0027application_credential\u0027 in token.methods, so OAuth1 access-token-scoped\nand ec2credential-derived tokens were never blocked from creating,\nlisting, reading, or deleting trusts -- unlike application_credential,\nwhich has had this restriction since LP#2148477.\n\nTwo more endpoints that mint a new persistent grant had the same gap:\n\n- users.py\u0027s _block_delegated_token_app_creds (guarding application\n  credential and access-rule CRUD) only checked trust_id/access_token_id,\n  so ec2credential-scoped tokens could create, list, read, and delete\n  application credentials.\n- os_oauth1.py\u0027s AuthorizeResource.put (PUT /v3/OS-OAUTH1/authorize) only\n  checked is_delegated_auth (trust/oauth1) and application_credential, so\n  an ec2credential-scoped token could authorize OAuth1 request tokens.\n\nAll three are extended to the same primary-auth-method allowlist used in\ncredentials.py, users.py, and token.py: any token whose methods aren\u0027t\nentirely primary auth methods is rejected outright. Trust-scoped tokens\nare deliberately not blocked from trust operations on trust_id alone --\nthat\u0027s the trust redelegation feature working as designed (a trustee\ncreating a further, narrower trust from one they were delegated) and\ntrustee self-service reads of their own trusts. A trust-scoped token\nwhose underlying method is itself delegated (an EC2 credential\u0027s blob\ncan embed a trust_id, see keystone.api.credentials._assign_unique_id) is\nstill caught by the method check regardless of trust scoping.\napplication_credential keeps its existing, documented opt-in escape\nhatch for trust management\n(allow_insecure_application_credential_trust_escalation) and its\nunrestricted/restricted distinction for creating further application\ncredentials (_check_unrestricted_application_credential); OAuth1 and EC2\ncredentials have no such use case and are blocked unconditionally\neverywhere.\n\nThis also closes off the underlying role-escalation path in trust\ncreation: trust role validation checks the trustor\u0027s full role\nassignments, not the requesting token\u0027s own scoped roles, so a\nnarrowly-scoped oauth1/ec2 token could previously delegate roles it was\nnever itself authorized for. Blocking those token types from trust\ncreation removes the path to that gap without needing to touch the\nvalidation itself.\n\nNeither the app-cred nor the OAuth1-authorize gap is reachable on\ncurrent master, where a separate middleware change globally rejects any\ncaller token with \u0027ec2credential\u0027 in its methods before Flask routing --\nbut that change is not backported to stable branches, so both gaps are\nlive there. Fixed at the source regardless, so the guard doesn\u0027t depend\non an unrelated middleware check remaining in place.\n\nAn empty token.methods list (e.g. an ec2credential-derived token that\nlost its methods on a fernet cache-miss round-trip -- ec2credential has\nno bit in the method bitmask) is also treated as delegated at all three\ncall sites: _PRIMARY_AUTH_METHODS.issuperset([]) is True, so without this\nan empty list would otherwise be accepted as \u0027all primary\u0027.\n\nConsolidated the three independent _PRIMARY_AUTH_METHODS copies (this\npatch, LP#2158538, LP#2159643) into keystone.api._shared.delegation,\nper gtema\u0027s review comment #16 -- now that all three land together the\nNameError-avoidance reason for keeping them separate no longer applies.\nAlso replaced the hardcoded method list with an operator-extensible one\n([auth] additional_primary_auth_methods): a hardcoded allowlist blocks\nany third-party auth plugin (e.g. a site-specific SSO integration) from\nreauthenticating/managing its own trusts, app-creds, and OAuth1 tokens,\nsince it can never appear in a list only keystone maintainers can edit.\n\nCloses-Bug: #2153453\nChange-Id: Ic8775eb0fdaa2330206023818ce18f76430fa45e\nAssisted-by: Claude Sonnet 5 \u003cnoreply@anthropic.com\u003e\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/54c5a5f11e7e14c2fcc9f81568bcf471f71013fe"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/54c5a5f11e7e14c2fcc9f81568bcf471f71013fe"}]},"branch":"refs/heads/stable/2026.1"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
