)]}'
{"id":"openstack%2Fkeystone~784558","triplet_id":"openstack%2Fkeystone~master~Iabc8fa117a63136712ea27b7619a8753ff414387","project":"openstack/keystone","branch":"master","hashtags":[],"change_id":"Iabc8fa117a63136712ea27b7619a8753ff414387","subject":"Adds support for JWT Tokens as authorization method (second try)","status":"NEW","created":"2021-04-02 10:40:00.000000000","updated":"2021-04-02 12:21:02.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":false,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"611bfb4756feaff0b7fee2f1d92b492ee3b91961","_number":784558,"virtual_id_number":784558,"owner":{"_account_id":33315,"name":"pregusia","email":"rafal@pregusia.pl","username":"pregusia"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2021-04-02 12:21:02.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-04-02 11:19:46.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2021-04-02 12:21:02.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"51855d267d1e25211a9b370b4135d076808da868","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":33315,"name":"pregusia","email":"rafal@pregusia.pl","username":"pregusia"},"date":"2021-04-02 10:40:00.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"3678475db273f80965fe0bc02fcb3a5f2bf3aa4a","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-02 11:19:46.000000000","message":"Patch Set 1:\n\nBuild succeeded (ARM64 pipeline).\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/c57c2156377444fd8bbf2feaa4cb9891 : SUCCESS in 36m 50s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/80c635f31a3a4f3792ea452979115883 : SUCCESS in 35m 12s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"611bfb4756feaff0b7fee2f1d92b492ee3b91961","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-02 12:21:02.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/6461e43f6dac408093ada44d79a6d450 : SUCCESS in 2m 29s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/1ed3fbe718a24b85b09297b2b68736de : SUCCESS in 19m 05s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/eb892b9be42e4898ad8cd06ce2ff9e6d : SUCCESS in 6m 00s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/74185422926d4324acf169759fba2257 : SUCCESS in 14m 01s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/eca0ef9ed58144128f6fdafb3096b497 : SUCCESS in 14m 37s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/498ff2127e274b0b898f7ee5306f5550 : SUCCESS in 13m 17s\n- grenade https://zuul.opendev.org/t/openstack/build/73ba40254a6144ffb1a795bd0cd1826f : SUCCESS in 1h 18m 27s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/39780f851cb64b3ba543a713b75dfceb : SUCCESS in 1h 35m 15s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/969da10a3a4f4c249f2ceab1e36c023d : SUCCESS in 40m 38s\n- keystone-dsvm-py3-functional-federation-ubuntu-focal https://zuul.opendev.org/t/openstack/build/c9692c1fba2d4029aacfa96bec6b922c : SUCCESS in 40m 36s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-focal-k2k https://zuul.opendev.org/t/openstack/build/d67bcf5fac154233b1389d6af8ef31a1 : SUCCESS in 40m 19s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/8693aa1f11f94dd0bc86e69241d9e5bc : SUCCESS in 13m 56s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/ade50ad8a02a42cf9cc899f9a427141a : FAILURE in 16m 05s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/b571b0ba1ba54ad9ae7937971fa5c59c : SUCCESS in 57m 23s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/52df65f408984e64ada339f0d1a7a1a0 : SUCCESS in 37m 32s","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"84db4ee64a3b7a54c2a34e6bce00840f81b8bd91","revisions":{"84db4ee64a3b7a54c2a34e6bce00840f81b8bd91":{"kind":"REWORK","_number":1,"created":"2021-04-02 10:40:00.000000000","uploader":{"_account_id":33315,"name":"pregusia","email":"rafal@pregusia.pl","username":"pregusia"},"ref":"refs/changes/58/784558/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/58/784558/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/58/784558/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/58/784558/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/58/784558/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/58/784558/1"}}},"commit":{"parents":[{"commit":"10057702ac361213e74472ec1d0d4e4c4a041f09","subject":"Merge \"Retry update_user when sqlalchemy raises StaleDataErrors\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/10057702ac361213e74472ec1d0d4e4c4a041f09"}]}],"author":{"name":"pregusia","email":"rafal@pregusia.pl","date":"2021-04-02 10:39:37.000000000","tz":120},"committer":{"name":"pregusia","email":"rafal@pregusia.pl","date":"2021-04-02 10:39:58.000000000","tz":120},"subject":"Adds support for JWT Tokens as authorization method (second try)","message":"Adds support for JWT Tokens as authorization method (second try)\n\nThis patch adds new authorization protocol - jwt_token.\nIt allows to access endpoint \u0027/v3/OS-FEDERATION/identity_providers/{IDP_NAME}/protocols/jwt_token/auth\u0027 (and obtain keystone auth token) using JWT token in Authorization header field.\nHeader value is checked against proper formating and JWT token is extracted from it.\nThen, token is validated against proper signature, issuer, expiration date and others.\nThen, if this end with success, payload from token is supplied to mapping engine, when new user is created.\n\nThis can be usefull in CLI-like API access to openstack with connection to OAuth or other IdP provider.\nYou can supply env like\n\texport OS_IDENTITY_PROVIDER\u003d\"idp_name\"\n\texport OS_PROTOCOL\u003d\"jwt_token\"\n\texport OS_AUTH_TYPE\u003d\"v3oidcclientcredentials\"\n\texport OS_ACCESS_TOKEN_ENDPOINT\u003d\".../oauth/token\"\n\texport OS_CLIENT_ID\u003d\u0027...\u0027\n\texport OS_CLIENT_SECRET\u003d\u0027...\u0027\n\nIn this scenario, JWT token is obtainer from oauth endpoint and then supplied to keystone, where is beeing parsed, validated.\nNew user is created (according to mappings) and access is given.\n\nChange-Id: Iabc8fa117a63136712ea27b7619a8753ff414387\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/84db4ee64a3b7a54c2a34e6bce00840f81b8bd91"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/84db4ee64a3b7a54c2a34e6bce00840f81b8bd91"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
