)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"change_message_id":"19e43da78491e1481e2fc0cc9a9c9b4c72740835","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"d27d2237_d88f5d17","updated":"2026-09-01 15:58:11.000000000","message":"I was mentioning it already in some other bug on launchpad. I think this is not sufficient, \"access\", \"access_token_id\", etc are part of the blob. Allowing to modify them is as bad. We should forbid update of credentials as such making them immutable as application credentials","commit_id":"42d80b5d284078328c4429d4d9995b26c8688d1b"},{"author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"change_message_id":"5a5365129dfad8a2836159e31e85246320708f27","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"1547b8e2_4f90b56b","updated":"2026-09-02 19:26:36.000000000","message":"This works as it is and we can add the blob rotation as a follow on patch to master.","commit_id":"42d80b5d284078328c4429d4d9995b26c8688d1b"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"724f03c3a0e46ded1cbe25ea72213058b3b59237","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"5471bb2e_294eeb30","in_reply_to":"d27d2237_d88f5d17","updated":"2026-09-02 09:52:25.000000000","message":"I left that in, since we carved out an exception specifically for this in bug 2150089 (blob rotation). I agree it should be immutable in the future. We can add a master only followup patch making it immutable (it will break tempest again, se we will need new tempest patches).\n\n\nfrom the commit msg:\n\nNarrow the existing, deprecated\nallow_insecure_admin_trust_cross_project_credentials_access\noption (LP#2150089) to ec2-type credentials only, matching its\ndocumented use case: an admin-role trust used to list/sync EC2\ncredentials.","commit_id":"42d80b5d284078328c4429d4d9995b26c8688d1b"}],"keystone/tests/unit/test_v3_credential.py":[{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"53006ecb7bf9fce0844fd9b1435b9531ab620e2a","unresolved":false,"context_lines":[{"line_number":1765,"context_line":"    def test_require_primary_auth_allows_custom_method_via_config(self):"},{"line_number":1766,"context_line":"        \"\"\"An operator-registered custom auth plugin is not mistaken for a"},{"line_number":1767,"context_line":"        delegated credential once listed in"},{"line_number":1768,"context_line":"        [auth] additional_primary_auth_methods."},{"line_number":1769,"context_line":"        \"\"\""},{"line_number":1770,"context_line":"        credentials_api.CONF.set_override("},{"line_number":1771,"context_line":"            \u0027additional_primary_auth_methods\u0027, [\u0027sso\u0027], group\u003d\u0027auth\u0027"}],"source_content_type":"text/x-python","patch_set":1,"id":"cf897cc7_6826b460","line":1768,"updated":"2026-08-25 17:57:48.000000000","message":"pep8: H405: multi line docstring summary not separated with an empty line","commit_id":"3a1409e4d4ebe0232b72ba2ec52b66bb53ab3b81"},{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"53006ecb7bf9fce0844fd9b1435b9531ab620e2a","unresolved":false,"context_lines":[{"line_number":1766,"context_line":"        \"\"\"An operator-registered custom auth plugin is not mistaken for a"},{"line_number":1767,"context_line":"        delegated credential once listed in"},{"line_number":1768,"context_line":"        [auth] additional_primary_auth_methods."},{"line_number":1769,"context_line":"        \"\"\""},{"line_number":1770,"context_line":"        credentials_api.CONF.set_override("},{"line_number":1771,"context_line":"            \u0027additional_primary_auth_methods\u0027, [\u0027sso\u0027], group\u003d\u0027auth\u0027"},{"line_number":1772,"context_line":"        )"}],"source_content_type":"text/x-python","patch_set":1,"id":"e06d2d9f_6161d9f6","line":1769,"updated":"2026-08-25 17:57:48.000000000","message":"pep8: H405: multi line docstring summary not separated with an empty line","commit_id":"3a1409e4d4ebe0232b72ba2ec52b66bb53ab3b81"},{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"53006ecb7bf9fce0844fd9b1435b9531ab620e2a","unresolved":false,"context_lines":[{"line_number":1767,"context_line":"        delegated credential once listed in"},{"line_number":1768,"context_line":"        [auth] additional_primary_auth_methods."},{"line_number":1769,"context_line":"        \"\"\""},{"line_number":1770,"context_line":"        credentials_api.CONF.set_override("},{"line_number":1771,"context_line":"            \u0027additional_primary_auth_methods\u0027, [\u0027sso\u0027], group\u003d\u0027auth\u0027"},{"line_number":1772,"context_line":"        )"},{"line_number":1773,"context_line":"        self.addCleanup("}],"source_content_type":"text/x-python","patch_set":1,"id":"0b2d4201_4863b678","line":1770,"updated":"2026-08-25 17:57:48.000000000","message":"pep8: H405: multi line docstring summary not separated with an empty line","commit_id":"3a1409e4d4ebe0232b72ba2ec52b66bb53ab3b81"},{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"53006ecb7bf9fce0844fd9b1435b9531ab620e2a","unresolved":false,"context_lines":[{"line_number":1768,"context_line":"        [auth] additional_primary_auth_methods."},{"line_number":1769,"context_line":"        \"\"\""},{"line_number":1770,"context_line":"        credentials_api.CONF.set_override("},{"line_number":1771,"context_line":"            \u0027additional_primary_auth_methods\u0027, [\u0027sso\u0027], group\u003d\u0027auth\u0027"},{"line_number":1772,"context_line":"        )"},{"line_number":1773,"context_line":"        self.addCleanup("},{"line_number":1774,"context_line":"            credentials_api.CONF.clear_override,"}],"source_content_type":"text/x-python","patch_set":1,"id":"caf8192c_a46ed3df","line":1771,"updated":"2026-08-25 17:57:48.000000000","message":"pep8: H405: multi line docstring summary not separated with an empty line","commit_id":"3a1409e4d4ebe0232b72ba2ec52b66bb53ab3b81"}]}
