)]}'
{"id":"openstack%2Fkeystone~908524","triplet_id":"openstack%2Fkeystone~master~Iffbe11c57c61bbd1b045a6567a9249c12dff403c","project":"openstack/keystone","branch":"master","topic":"secure-rbac","attention_set":{},"removed_from_attention_set":{"7973":{"account":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"last_update":"2024-02-12 17:38:10.000000000","reason":"Change was submitted"},"7414":{"account":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"last_update":"2024-02-12 16:09:07.000000000","reason":"\u003cGERRIT_ACCOUNT_7414\u003e replied on the change","reason_account":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}},"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2024-02-10 19:25:43.000000000","reason":"\u003cGERRIT_ACCOUNT_14250\u003e replied on the change","reason_account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}}},"hashtags":[],"change_id":"Iffbe11c57c61bbd1b045a6567a9249c12dff403c","subject":"Normalize policy checks for domain-scoped tokens","status":"MERGED","created":"2024-02-08 20:47:47.000000000","updated":"2024-02-12 17:39:45.000000000","submitted":"2024-02-12 17:38:10.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"908524-secure-rbac","meta_rev_id":"39c8e6c28b2ce9930c057e394ebf8275c500d3a5","_number":908524,"virtual_id_number":908524,"owner":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2024-02-12 17:38:10.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":2,"date":"2024-02-12 16:09:07.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":2,"date":"2024-02-10 19:25:43.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":1,"date":"2024-02-12 16:09:07.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2024-02-08 20:59:36.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2024-02-08 22:18:08.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2024-02-09 20:24:09.000000000","updated_by":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"},{"updated":"2024-02-09 20:24:09.000000000","updated_by":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"reviewer":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"state":"REVIEWER"}],"messages":[{"id":"d0750037db3ccc54f5cde052937dc093c4922648","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"date":"2024-02-08 20:47:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"fe1ec7a16ff08522f6a1a7c31182aaa9120896fd","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-08 20:59:36.000000000","message":"Patch Set 1:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/741b05aa744845b9b3437bbf556a6a72\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/1de73c0cb333467fad5f53e2ac6e33ed : FAILURE in 10m 09s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/56e7cfe24f684ad6ae32a0f200732dc5 : FAILURE in 11m 00s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"4ece68119549513ba09e686c9e3f877352cf2b1a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-08 22:18:08.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\nhttps://zuul.opendev.org/t/openstack/buildset/fdb517610e42403dad7cf5685cefa68b\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/99a27327bf5449e1a8cdbbe2e6fbdb5c : FAILURE in 13m 41s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e2686ec16f554f4b80c3135a2b972266 : SUCCESS in 4m 37s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/d5e5db2915c246d59747294ef1a6815b : FAILURE in 11m 59s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/9f65beae62554c6e9eb8e444d785b603 : FAILURE in 9m 40s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4ebcf64552db4204b6b5593eb99ac330 : SUCCESS in 11m 20s\n- grenade https://zuul.opendev.org/t/openstack/build/cbffda81963e49538824371f3440c2d2 : FAILURE in 55m 34s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/4226db48739a44d09401f65533c8397d : SUCCESS in 1h 28m 23s\n- keystone-tox-py310-with-sqlalchemy-2x https://zuul.opendev.org/t/openstack/build/7a7d4eeb2f514c6c8c0b5578ec64ced3 : FAILURE in 14m 38s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/65f3444da66e494d8156ed75179a3858 : SUCCESS in 20m 38s\n- keystone-dsvm-py3-functional-fips https://zuul.opendev.org/t/openstack/build/c445c58184344a749fede54bb6cbb981 : SUCCESS in 37m 34s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy https://zuul.opendev.org/t/openstack/build/ccf7f790a9034229ab2a55a8f6456441 : FAILURE in 18m 44s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy-k2k https://zuul.opendev.org/t/openstack/build/78448400a0c54ceea438451d8ae9b6d5 : SUCCESS in 33m 22s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/775713ed8492435ea135929cdea8d064 : SUCCESS in 24m 01s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/5e5d59e03a0f4f6c8c839fdf795a1b0b : FAILURE in 12m 03s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/2ae4676e2c9242bfa0489f28c69eb321 : SUCCESS in 55m 35s","accounts_in_message":[],"_revision_number":1},{"id":"c5563845668f5bdfc85ccd59e6b07e1de81302d1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"date":"2024-02-09 17:34:14.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1\n","accounts_in_message":[],"_revision_number":2},{"id":"908a567d6e50a22b94993ed46d91e7a3aff6a3b4","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-09 17:55:27.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/c7c7e1fc9741419ca79fe977486ae32d\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/cc2f2ac8c68f452d9507bce772769862 : SUCCESS in 20m 16s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/49faa91c2f564fbe858a096572f82b3c : SUCCESS in 12m 49s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"4e9575dbb053d9fed03fec1fc3556c23612a4eb8","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-09 18:51:49.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f22ad7187be044b6805cc0c3e699dd6f\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/e6c94baee5204ecf80ae9515d1f5d79a : SUCCESS in 14m 33s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/d5e7526cf9a74503afa771161c628711 : SUCCESS in 4m 48s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/f96521b454fd4942a5096a2b5578b021 : SUCCESS in 14m 32s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/406bcb9b39864b24a407b51c62880afa : SUCCESS in 8m 17s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/bc872fa91d104620969c92e3e93784f0 : SUCCESS in 12m 00s\n- grenade https://zuul.opendev.org/t/openstack/build/b868f6f6c26c4a5799ee102f2ec94cbf : SUCCESS in 51m 40s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/a7c2c25727e74050a9aca6273853e3f0 : SUCCESS in 1h 16m 22s\n- keystone-tox-py310-with-sqlalchemy-2x https://zuul.opendev.org/t/openstack/build/fec863b641e74422acc2471f4fdfafaa : SUCCESS in 14m 35s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/57e2898e87144ac09bde2a03554cf4da : SUCCESS in 33m 08s\n- keystone-dsvm-py3-functional-fips https://zuul.opendev.org/t/openstack/build/63f45094f1e941738fa1c34c35cad292 : SUCCESS in 47m 39s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy https://zuul.opendev.org/t/openstack/build/2ac9846fd5be4148a82e39892c66a2da : FAILURE in 41m 09s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy-k2k https://zuul.opendev.org/t/openstack/build/85839e1aa16449aeaf92d5e6f41e4af2 : SUCCESS in 32m 49s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/8178071b2c6e4ef8a08392cdfffd611f : SUCCESS in 11m 05s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/ac69bedd3f96456f923a168112cac84d : FAILURE in 23m 45s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/d9ae5b1295e54048b10d5cd339ea8484 : SUCCESS in 40m 52s","accounts_in_message":[],"_revision_number":2},{"id":"de030ff42150e1e101ee8f04b17723ac10a91860","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2024-02-10 19:25:43.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"fda7d8f9cd8577d942207dad014051c0f995c9d9","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2024-02-12 16:09:07.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":2},{"id":"a56413084d6e200d2a49c249495a1b8373eec0a3","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-12 16:09:41.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"f66e4378774f311a0008f34aea69cdfb2b37e09f","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-12 17:38:10.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/94a90de7fe064c88bd46e6734f00bda8\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/ca313c74a4104c2fbc726db1bf7c4b8f : SUCCESS in 5m 10s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/4dc49dc60e1846acbb0542c8e1c7c31b : SUCCESS in 15m 53s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/d59d0e9ac03f4e0f9bda2ddd79ba7f3b : SUCCESS in 8m 54s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/7e095e8d16d9440497312d3bececcd33 : SUCCESS in 12m 11s\n- grenade https://zuul.opendev.org/t/openstack/build/504a368e33514b879284767c548d3fc8 : SUCCESS in 47m 53s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/2672ee1fd28647fea88cf8dc99c1b96a : SUCCESS in 1h 27m 17s\n- keystone-tox-py310-with-sqlalchemy-2x https://zuul.opendev.org/t/openstack/build/1e24228dfd2f4b69953d15cc877650a1 : SUCCESS in 14m 04s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/6ea6aab6e5044491bb8cbbbc21bc2ab9 : SUCCESS in 26m 27s\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy-k2k https://zuul.opendev.org/t/openstack/build/747045c068374c12aa0c9c037d77d5b0 : SUCCESS in 29m 12s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/2e679c2066db42e493fd3b84572859f3 : SUCCESS in 59m 49s","accounts_in_message":[],"_revision_number":2},{"id":"56758fdb8ca0cf9616c23d1606ef631bb3bca2ba","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-12 17:38:10.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"39c8e6c28b2ce9930c057e394ebf8275c500d3a5","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2024-02-12 17:39:45.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/93994ea6240f48979cbe8364e7655c62\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a2172ceec81947c19de964a0d45f7d08 : SUCCESS in 1m 14s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"7dc175a41f92e3f01cf26912431d0f2c98a03b32","revisions":{"627d595596db7be7f68d7fd3290462986c098fba":{"kind":"REWORK","_number":1,"created":"2024-02-08 20:47:47.000000000","uploader":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"ref":"refs/changes/24/908524/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/24/908524/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/24/908524/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/24/908524/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/24/908524/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/24/908524/1"}}},"commit":{"parents":[{"commit":"db0ff104763b6da4d661bf0c5cc9814ea3f18fc8","subject":"reno: Update master for unmaintained/yoga","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/db0ff104763b6da4d661bf0c5cc9814ea3f18fc8"}]}],"author":{"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","date":"2024-02-08 20:36:38.000000000","tz":-360},"committer":{"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","date":"2024-02-08 20:47:43.000000000","tz":-360},"subject":"Normalize policy checks for domain-scoped tokens","message":"Normalize policy checks for domain-scoped tokens\n\nThis patch fixes an inconsistency in the policies for role_assignment\nwhere the target object used for policy enforcement was being created\nwith different properties depending on the request query string.\n\nThis required policies to be written in two differnt ways to validate\ndomain IDs for domain-scoped requests.  e.g. checking for domain reader\nwas using both:\n\n    role:reader and domain_id:%(target.domain_id)s\n\nand\n\n    role:reader and domain_id:%(target.project.domain_id)s\n\nWith the former only being populated for GET /v3/role_assignments and\nthe latter only being populated for GET\n/v3/role_assignments?scope.project.id\u003dSOME_ID\n\nThis patch fixes the target object so that only target.domain_id needs\nto be checked for domain-scoped tokens.\n\nChange-Id: Iffbe11c57c61bbd1b045a6567a9249c12dff403c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/627d595596db7be7f68d7fd3290462986c098fba"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/627d595596db7be7f68d7fd3290462986c098fba"}]},"branch":"refs/heads/master"},"7dc175a41f92e3f01cf26912431d0f2c98a03b32":{"kind":"REWORK","_number":2,"created":"2024-02-09 17:34:14.000000000","uploader":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"ref":"refs/changes/24/908524/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/24/908524/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/24/908524/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/24/908524/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/24/908524/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/24/908524/2"}}},"commit":{"parents":[{"commit":"db0ff104763b6da4d661bf0c5cc9814ea3f18fc8","subject":"reno: Update master for unmaintained/yoga","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/db0ff104763b6da4d661bf0c5cc9814ea3f18fc8"}]}],"author":{"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","date":"2024-02-08 20:36:38.000000000","tz":-360},"committer":{"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","date":"2024-02-09 17:33:51.000000000","tz":-360},"subject":"Normalize policy checks for domain-scoped tokens","message":"Normalize policy checks for domain-scoped tokens\n\nThis patch fixes an inconsistency in the policies for role_assignment\nwhere the target object used for policy enforcement was being created\nwith different properties depending on the request query string.\n\nThis required policies to be written in two differnt ways to validate\ndomain IDs for domain-scoped requests.  e.g. checking for domain reader\nwas using both:\n\n    role:reader and domain_id:%(target.domain_id)s\n\nand\n\n    role:reader and domain_id:%(target.project.domain_id)s\n\nWith the former only being populated for GET /v3/role_assignments and\nthe latter only being populated for GET\n/v3/role_assignments?scope.project.id\u003dSOME_ID\n\nThis patch fixes the target object so that only target.domain_id needs\nto be checked for domain-scoped tokens.\n\nChange-Id: Iffbe11c57c61bbd1b045a6567a9249c12dff403c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7dc175a41f92e3f01cf26912431d0f2c98a03b32"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7dc175a41f92e3f01cf26912431d0f2c98a03b32"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
