)]}'
{"id":"openstack%2Fkeystone~966583","triplet_id":"openstack%2Fkeystone~master~If5b83feabc670ced54ef12fe7826267af7e3419d","project":"openstack/keystone","branch":"master","attention_set":{},"removed_from_attention_set":{"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2025-12-05 15:45:04.000000000","reason":"\u003cGERRIT_ACCOUNT_14250\u003e replied on the change","reason_account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}},"27900":{"account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"last_update":"2025-12-05 18:11:02.000000000","reason":"Change was submitted"},"1004":{"account":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"last_update":"2025-11-14 16:19:30.000000000","reason":"\u003cGERRIT_ACCOUNT_1004\u003e replied on the change","reason_account":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"}}},"hashtags":[],"change_id":"If5b83feabc670ced54ef12fe7826267af7e3419d","subject":"Invalidate token of user disabled in readonly backend","status":"MERGED","created":"2025-11-10 15:09:34.000000000","updated":"2025-12-05 18:12:50.000000000","submitted":"2025-12-05 18:11:02.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":4,"unresolved_comment_count":1,"has_review_started":true,"submission_id":"966583","meta_rev_id":"0591dfb127eeb828c149754dba767bc176d4c767","_number":966583,"virtual_id_number":966583,"owner":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2025-12-05 18:11:02.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":2,"date":"2025-12-05 15:47:19.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":2,"date":"2025-12-05 15:45:04.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":1,"date":"2025-11-14 16:19:30.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":1,"date":"2025-12-05 15:47:26.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"}],"REVIEWER":[{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2025-11-10 15:52:32.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2025-11-10 17:17:35.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2025-11-10 21:07:43.000000000","updated_by":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"reviewer":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"state":"CC"},{"updated":"2025-11-10 21:34:35.000000000","updated_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"},{"updated":"2025-11-13 18:58:23.000000000","updated_by":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"reviewer":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"state":"REVIEWER"},{"updated":"2025-12-05 15:47:19.000000000","updated_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"reviewer":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"state":"REVIEWER"}],"messages":[{"id":"d2381fe015bee0112e81329092a08a27683a6439","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-10 15:09:34.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"c9564d411d26d557887b8c2673071c706198f33c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-10 15:10:17.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"a5c04351b54ef1f0daa0dd9405025ca9108ec5fa","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-10 15:10:52.000000000","message":"Uploaded patch set 3: Commit message was updated.","accounts_in_message":[],"_revision_number":3},{"id":"2fa89a3c616850f2eaffad9328d64329712f35cb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-10 15:17:12.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"75766cca1ca1794f941a7d47e145d6784a4c82fa","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-10 15:52:32.000000000","message":"Patch Set 4:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/756b28692a0141678573bd2577efdea2\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/8f96c7146cd046c6a17293acfd789622 : SUCCESS in 29m 31s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/628b92b37a7545f2bb93e4ff671ea5ee : SUCCESS in 25m 02s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/e4f0b0dcda75479f8d8c619a744d0834 : SUCCESS in 33m 01s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"34c00fe6db7e2b4d9e983fa5185121f5b64ffbc0","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-10 17:17:35.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f1e00c415eb146cd9cc3aad57313ac2c\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/d36d201669d549b79d5f22391b8f52ab : SUCCESS in 15m 18s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/90bc285e4bdc424b9fab59c8251104d9 : SUCCESS in 6m 27s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/c1358e1166bc44768f6023c22147d595 : SUCCESS in 12m 23s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/7994e2226f20420aa6408ce83ee4b4a0 : SUCCESS in 16m 41s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/0d5abbff8ea9432680e5065d943ed034 : SUCCESS in 6m 56s\n- grenade https://zuul.opendev.org/t/openstack/build/f17548bce5da4d8ab533f7f1daabbbdc : SUCCESS in 43m 17s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/263e0f2cb649438393f51dba25b5916a : SUCCESS in 1h 47m 02s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/35c785b425bc4ce0bebbfded44ad6f3c : SUCCESS in 16m 25s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/70aded5393b24219835931bf26a540cd : SUCCESS in 27m 49s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/8087fae224fe44ffb33925247cfcf0cb : FAILURE in 15m 19s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/362e2d01315840ca8a421f3c3e2695ac : FAILURE in 29m 37s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/59c37232172f45b9b5424a2e27868994 : SUCCESS in 28m 38s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/47696aec9fea43f396914771585e196d : SUCCESS in 19m 06s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/fa50b36e01cb41d2af88eba41cdfcb7c : SUCCESS in 40m 58s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/4f6ad65aaa8f45b1a38c8cc243a510db : SUCCESS in 53m 04s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/d263b07ee17a4572984f518512af4154 : FAILURE in 40m 17s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/78feb6c40bd440e781559005f035c66b : SUCCESS in 6m 37s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"cf6ab808da4f09eaaf5947b7aa35958a493e34ae","author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"date":"2025-11-10 21:07:43.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"d3761eb8db24cd0e00c51675d7895efdcac749e3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2025-11-10 21:34:27.000000000","message":"Patch Set 5: Commit message was updated.\n\nOutdated Votes:\n* Verified+1\n","accounts_in_message":[],"_revision_number":5},{"id":"a544cbcc6e28bd22be29a027843a996cafd70ac0","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2025-11-10 21:34:35.000000000","message":"Patch Set 5: Code-Review+2","accounts_in_message":[],"_revision_number":5},{"id":"f00ad79850a83b6c53b553c537dddee3257d4428","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-10 21:57:56.000000000","message":"Patch Set 5:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2a106e0882334e30aea36299b8b47b73\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/328dcc6c19584efabf32395d285851e4 : SUCCESS in 16m 48s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/c9ea9bac33b240d49be6a62b83dee200 : SUCCESS in 16m 48s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/a98f33b3d2c8479aaf2ccc57bad10a4d : SUCCESS in 21m 51s (non-voting)","accounts_in_message":[],"_revision_number":5},{"id":"1b34ad32f396ff0dcedb479225e0dc311f4315d6","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-10 23:16:32.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/7c5d2d136a94447ab2ff13c6c0a2ab87\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/2629430aaab444fab548f38206b82f79 : SUCCESS in 18m 35s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/f7c620face15474ca8e2c66ba8a6cf6e : SUCCESS in 6m 08s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/0d0c877ebc7a40f3ad8053dc18654379 : SUCCESS in 11m 46s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/23a645d85dd248f8b106e25ed7373ee8 : SUCCESS in 17m 35s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e0ce51446c174bc391e2c0a7652a4fb2 : SUCCESS in 14m 15s\n- grenade https://zuul.opendev.org/t/openstack/build/e5d0d027f8054ad994bff7eab846a209 : SUCCESS in 57m 28s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/67ce049e434a4d11a837fea9636dfe87 : SUCCESS in 1h 37m 10s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/eac1a23c3d11468aaca58b4293df0bf9 : SUCCESS in 17m 11s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/b4f508bf30a64b47933970a516611567 : SUCCESS in 31m 33s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/0b7d039fa0804e5abfde1bca0588de43 : FAILURE in 11m 03s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/308f41d471dd4659848f7a5d846d9be3 : FAILURE in 28m 35s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/086824c4035a494caab76a5fd5882069 : SUCCESS in 20m 47s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/07becf04af6740a99708d1a0df65a7d1 : SUCCESS in 29m 39s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/e286fe9ca68a4ae485561e42ea75bfcb : SUCCESS in 22m 41s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/8cdd12eef0924eb284b6e58df41f42e5 : SUCCESS in 35m 25s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/2c844ece2b344309bbcd96cb68b00762 : FAILURE in 22m 10s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/d50a3fea520c435dba4198cee7ce6af9 : SUCCESS in 6m 50s (non-voting)","accounts_in_message":[],"_revision_number":5},{"id":"59e07b8ac4b4aaf664e358bde12880f5b0b29fbd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-11 09:48:24.000000000","message":"Uploaded patch set 6.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1\n","accounts_in_message":[],"_revision_number":6},{"id":"11b8d7abcabd2dccdb900c586f1f15e5f586decc","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-11 09:48:57.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"6f01f10ebc573298bc9bd96d09f51ce15193ebdc","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-11 10:22:32.000000000","message":"Patch Set 6:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/fb4fdda237ea4fd5808e8baa5559c7b8\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/64c2e345edb643369145e7ca1d1e6b22 : SUCCESS in 32m 07s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/b77101d944df49ce8f4120b271cd5525 : SUCCESS in 31m 51s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/d2c35cd355344b4c9d694352a913d52c : SUCCESS in 27m 18s (non-voting)","accounts_in_message":[],"_revision_number":6},{"id":"f828175532ac0149a750feaa3c9b660e38411688","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-11 11:56:41.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/e5f3de2337bc48749c6c52131daf0d81\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/1d13c61a42814addacf4b3d2018f5e45 : SUCCESS in 19m 55s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/b9a9e407483240cb85f3cc6e81750fe0 : SUCCESS in 7m 20s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/ef6650f7d48b479b977c9e0ef649cbd3 : SUCCESS in 13m 45s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/bc6feb89890f427dbe58f573a655f5d2 : SUCCESS in 17m 53s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/86130af9cf3544be98571dd8f0978309 : SUCCESS in 14m 31s\n- grenade https://zuul.opendev.org/t/openstack/build/91143f91ead74412a0fa67166fbcea12 : SUCCESS in 49m 16s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/5db335fde96f40c088612a64019d0e08 : SUCCESS in 2h 03m 29s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/8289d639efe84caf8e93242f2587eca3 : SUCCESS in 8m 41s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/fdbfba59e4174d3a8dbd30024d7130eb : SUCCESS in 16m 27s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/9c28d8770fe3425c82cb38f8af6c12d9 : SUCCESS in 14m 23s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/4365d2ae9dd84539a49e9f7afa89bca3 : FAILURE in 10m 09s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/02efc63a0f044e0b8c993a1e85d37340 : FAILURE in 15m 14s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/07231917ed884a579905d287ffdbe254 : SUCCESS in 30m 25s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/71826d86482e40a3b8dc9dfbfb9677b2 : SUCCESS in 31m 31s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/59776b2572ed46aab37f866f9c1734dd : SUCCESS in 28m 08s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/41d64626c48e4b57a8f5f6858b160709 : SUCCESS in 1h 14m 35s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/6fbc3b66ae2b4d52b2643b900a47c557 : FAILURE in 41m 05s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/3dfacb35a5c64035affbced33a8f5a57 : SUCCESS in 6m 34s (non-voting)","accounts_in_message":[],"_revision_number":6},{"id":"fd40ea55cc3102ab51707f2bfc437b226bc11af0","author":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"date":"2025-11-13 18:58:23.000000000","message":"Patch Set 6: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"c7a7ef86ec0e027c6c076c5e7693980005f2d2bd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-14 08:13:56.000000000","message":"Uploaded patch set 7.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1\n","accounts_in_message":[],"_revision_number":7},{"id":"9bcb3e90bf6a3a2fdf93e39e92243920d7f4aa04","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2025-11-14 08:14:48.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"6572bdfb0b475a406f65ccb85561d0a1a50628cc","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-14 08:51:41.000000000","message":"Patch Set 7:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f0ce4ae77b57440a99966584882c07fe\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/35e81521fdba4fa1ae9650a1367f9942 : SUCCESS in 26m 35s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/f415ca171b22403d84c47b753339e98d : SUCCESS in 26m 48s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/2e6263d952de49f3824570cb928c1a42 : SUCCESS in 35m 55s (non-voting)","accounts_in_message":[],"_revision_number":7},{"id":"832168f48c1f63cd8597ef0f85dd26a8bbf2a15f","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-11-14 10:01:11.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/89807eb2a0ad4a33ab629dc92c71c172\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/32bcebf7a7f6438cb3971e4f59b9345a : SUCCESS in 17m 27s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/41da3511976c46208a3c84181bcca1d5 : SUCCESS in 4m 19s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/cc8c438313fd406fa035ec061380c41f : SUCCESS in 11m 56s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/ab6ec0a100b445488a2472a327f3cbd4 : SUCCESS in 15m 34s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/54144da829ec4968b47e3de76205f949 : SUCCESS in 13m 30s\n- grenade https://zuul.opendev.org/t/openstack/build/64cbeea8a8324f30b579c31946764618 : SUCCESS in 33m 16s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/c23cd63c97d74f1ba712ea2e9d33036c : SUCCESS in 1h 42m 04s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/0f7e7fe08acf40a2893f6e2d01be5202 : SUCCESS in 9m 29s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/c609abf2abe641999ff4ae3a6f01fdcc : SUCCESS in 18m 48s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/edcdf60b81c64fdc886705503e5101d6 : SUCCESS in 30m 33s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/acb31f33ab7e454bb9b56837cd2266ee : FAILURE in 18m 26s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/bef6ab5b90a640e2b65499705c52685d : FAILURE in 11m 55s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/1acb546d96004d20aa3d47bc99d6932d : SUCCESS in 15m 33s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/d563b700be7c44b8989cfad1a90b1613 : SUCCESS in 29m 49s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/4ce7a965938145b3ac8bfadcf1c833cc : SUCCESS in 31m 37s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/f5acc3ed987545fc825bf1f75a303caa : SUCCESS in 58m 10s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/3425c0dfb197407c9964b7d981e206f2 : FAILURE in 17m 25s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/b02c5dddc3c340ac98262712455f7ae6 : SUCCESS in 6m 30s (non-voting)","accounts_in_message":[],"_revision_number":7},{"id":"5cb24dc600328304d7a43109c2afce70a932e3d3","author":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"date":"2025-11-14 16:19:30.000000000","message":"Patch Set 7: Code-Review+1","accounts_in_message":[],"_revision_number":7},{"id":"8417b69142e5da1fb3b654f8e0d38eafdbe3379c","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2025-12-05 15:45:04.000000000","message":"Patch Set 7: Code-Review+2","accounts_in_message":[],"_revision_number":7},{"id":"aa247c864d72af85450efbfda946dbb8360571e9","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2025-12-05 15:47:19.000000000","message":"Patch Set 7: Code-Review+2","accounts_in_message":[],"_revision_number":7},{"id":"b489a1cc0f130c04996619d4b01666989eb343fe","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2025-12-05 15:47:26.000000000","message":"Patch Set 7: Workflow+1","accounts_in_message":[],"_revision_number":7},{"id":"473e65bd74fb529592a9c4cde796219a4a088879","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-05 15:47:59.000000000","message":"Patch Set 7: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":7},{"id":"e6288b5271980e855db48960006fce2dfee913ae","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-05 18:11:02.000000000","message":"Patch Set 7: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/753fac7ddb914661947b3e8e803d8a7a\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a53af7136d7b46568f13c93a76f60655 : SUCCESS in 8m 51s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/7b586d126019420997fc4846a591bb63 : SUCCESS in 11m 36s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/f9b024796e5b40a18f578a574a629820 : SUCCESS in 15m 47s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/dbea5d8a33c74a3ebf726053b72ffee0 : SUCCESS in 15m 13s\n- grenade https://zuul.opendev.org/t/openstack/build/5bd54dc1ca2a4f90b48fccf74b78d9f5 : SUCCESS in 1h 02m 45s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/e2584e7d0bbc4706af049d6c36e17e6e : SUCCESS in 1h 56m 33s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/0aaefb728bd2493aa2c02ce73c88ccbd : SUCCESS in 13m 11s\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/77ce52dfaecf417dbaf13c6fc1d5f93f : SUCCESS in 14m 33s\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/8bab3d440f2946f487e8f6952102d986 : SUCCESS in 27m 29s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/19b571a9509a4bbaab5bb55b932bb559 : SUCCESS in 31m 17s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/145c388ee30e4405a91f1066e209f708 : FAILURE in 38m 26s (non-voting)","accounts_in_message":[],"_revision_number":7},{"id":"d92adc92991f464bc8fc059f29c437e8d4e56282","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-05 18:11:02.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":7},{"id":"0591dfb127eeb828c149754dba767bc176d4c767","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-05 18:12:50.000000000","message":"Patch Set 7:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/a0dfe340488b4cb6931414430aab6ad1\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/b29bb9a9437d416e98e8433d9025917a : SUCCESS in 52s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/a137b8d515414431978bdfb77d8a1b7a : SUCCESS in 39s","accounts_in_message":[],"_revision_number":7}],"current_revision_number":7,"current_revision":"c63efe1df102bcd6d39361bef45baf4ecdb7f1bd","revisions":{"94316ef9298a06aa4d932700f1c56371718c95f0":{"kind":"REWORK","_number":1,"created":"2025-11-10 15:09:34.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/83/966583/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/83/966583/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/83/966583/1"}}},"commit":{"parents":[{"commit":"c0a2c6b0bae01816b7da552fc1e1b83a8effe938","subject":"Merge \"fix ldap \u0027enabled\u0027 setting not interpreted as boolean\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c0a2c6b0bae01816b7da552fc1e1b83a8effe938"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"subject":"Invalidate token of user disabled in readonly backend","message":"Invalidate token of user disabled in readonly backend\n\nWe support custom identity plugins. They (and also LDAP backend) may be\nconsidered as a read-only (not supporting user data modification through\nKeystone API). When a user of such backend is disabled in the remote\nsystem Keystone will never learn about that and as such tokens for those\nusers will remain active. They cannot be renewed, but still they stay\nvalid.\nIn order to address this situation we need to do additional steps in the\ntoken validation and identify the current state of the user in the\nbackend. Due to the use of the token caching it is not possible to reuse\nnormal token validation functionality (it will never gets invalidated as\nsuch). In order to keep performance impact as low as possible modify the\ntoken validation as following:\n- regular checks\n- revocation check\n- if token is still active and revoke check passed fetch current user\n  data. When user is disabled - log a warning (explaining the situation)\n  and raise `UserDisabled` exception.\n\nSince Keystone also does not receive a message when user is reactivated\n(i.e. it was accidentally disabled) we cannot use the same approach as\nfor regular user disabling and generate a token revocation event. This\nwould cause the user to be locked out until the revocation event\nexpires.\n\nFixes: 2122615\n\nChange-Id: If5b83feabc670ced54ef12fe7826267af7e3419d\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/94316ef9298a06aa4d932700f1c56371718c95f0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/94316ef9298a06aa4d932700f1c56371718c95f0"}]},"branch":"refs/heads/master"},"5533f47c6e76eb33dffcebceef841d7aeb24be4e":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2025-11-10 15:10:17.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/83/966583/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/83/966583/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/83/966583/2"}}},"commit":{"parents":[{"commit":"c0a2c6b0bae01816b7da552fc1e1b83a8effe938","subject":"Merge \"fix ldap \u0027enabled\u0027 setting not interpreted as boolean\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c0a2c6b0bae01816b7da552fc1e1b83a8effe938"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:10:07.000000000","tz":60},"subject":"Invalidate token of user disabled in readonly backend","message":"Invalidate token of user disabled in readonly backend\n\nWe support custom identity plugins. They (and also LDAP backend) may be\nconsidered as a read-only (not supporting user data modification through\nKeystone API). When a user of such backend is disabled in the remote\nsystem Keystone will never learn about that and as such tokens for those\nusers will remain active. They cannot be renewed, but still they stay\nvalid.\nIn order to address this situation we need to do additional steps in the\ntoken validation and identify the current state of the user in the\nbackend. Due to the use of the token caching it is not possible to reuse\nnormal token validation functionality (it will never gets invalidated as\nsuch). In order to keep performance impact as low as possible modify the\ntoken validation as following:\n- regular checks\n- revocation check\n- if token is still active and revoke check passed fetch current user\n  data. When user is disabled - log a warning (explaining the situation)\n  and raise `UserDisabled` exception.\n\nSince Keystone also does not receive a message when user is reactivated\n(i.e. it was accidentally disabled) we cannot use the same approach as\nfor regular user disabling and generate a token revocation event. This\nwould cause the user to be locked out until the revocation event\nexpires.\n\nFixes: #2122615\n\nChange-Id: If5b83feabc670ced54ef12fe7826267af7e3419d\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5533f47c6e76eb33dffcebceef841d7aeb24be4e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5533f47c6e76eb33dffcebceef841d7aeb24be4e"}]},"branch":"refs/heads/master"},"ca3a1692cb1bb16774be5784ad8e41adfafb4e61":{"kind":"NO_CODE_CHANGE","_number":3,"created":"2025-11-10 15:10:52.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/83/966583/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/83/966583/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/83/966583/3"}}},"commit":{"parents":[{"commit":"c0a2c6b0bae01816b7da552fc1e1b83a8effe938","subject":"Merge \"fix ldap \u0027enabled\u0027 setting not interpreted as boolean\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c0a2c6b0bae01816b7da552fc1e1b83a8effe938"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:10:41.000000000","tz":60},"subject":"Invalidate token of user disabled in readonly backend","message":"Invalidate token of user disabled in readonly backend\n\nWe support custom identity plugins. They (and also LDAP backend) may be\nconsidered as a read-only (not supporting user data modification through\nKeystone API). When a user of such backend is disabled in the remote\nsystem Keystone will never learn about that and as such tokens for those\nusers will remain active. They cannot be renewed, but still they stay\nvalid.\nIn order to address this situation we need to do additional steps in the\ntoken validation and identify the current state of the user in the\nbackend. Due to the use of the token caching it is not possible to reuse\nnormal token validation functionality (it will never gets invalidated as\nsuch). In order to keep performance impact as low as possible modify the\ntoken validation as following:\n- regular checks\n- revocation check\n- if token is still active and revoke check passed fetch current user\n  data. When user is disabled - log a warning (explaining the situation)\n  and raise `UserDisabled` exception.\n\nSince Keystone also does not receive a message when user is reactivated\n(i.e. it was accidentally disabled) we cannot use the same approach as\nfor regular user disabling and generate a token revocation event. This\nwould cause the user to be locked out until the revocation event\nexpires.\n\nCloses-bug: #2122615\n\nChange-Id: If5b83feabc670ced54ef12fe7826267af7e3419d\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/ca3a1692cb1bb16774be5784ad8e41adfafb4e61"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/ca3a1692cb1bb16774be5784ad8e41adfafb4e61"}]},"branch":"refs/heads/master"},"058d4a1715dfbd79e48871a04101cb23db304f24":{"kind":"REWORK","_number":4,"created":"2025-11-10 15:17:12.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/83/966583/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/83/966583/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/83/966583/4"}}},"commit":{"parents":[{"commit":"c0a2c6b0bae01816b7da552fc1e1b83a8effe938","subject":"Merge \"fix ldap \u0027enabled\u0027 setting not interpreted as boolean\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c0a2c6b0bae01816b7da552fc1e1b83a8effe938"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:17:04.000000000","tz":60},"subject":"Invalidate token of user disabled in readonly backend","message":"Invalidate token of user disabled in readonly backend\n\nWe support custom identity plugins. They (and also LDAP backend) may be\nconsidered as a read-only (not supporting user data modification through\nKeystone API). When a user of such backend is disabled in the remote\nsystem Keystone will never learn about that and as such tokens for those\nusers will remain active. They cannot be renewed, but still they stay\nvalid.\nIn order to address this situation we need to do additional steps in the\ntoken validation and identify the current state of the user in the\nbackend. Due to the use of the token caching it is not possible to reuse\nnormal token validation functionality (it will never gets invalidated as\nsuch). In order to keep performance impact as low as possible modify the\ntoken validation as following:\n- regular checks\n- revocation check\n- if token is still active and revoke check passed fetch current user\n  data. When user is disabled - log a warning (explaining the situation)\n  and raise `UserDisabled` exception.\n\nSince Keystone also does not receive a message when user is reactivated\n(i.e. it was accidentally disabled) we cannot use the same approach as\nfor regular user disabling and generate a token revocation event. This\nwould cause the user to be locked out until the revocation event\nexpires.\n\nCloses-bug: #2122615\n\nChange-Id: If5b83feabc670ced54ef12fe7826267af7e3419d\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/058d4a1715dfbd79e48871a04101cb23db304f24"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/058d4a1715dfbd79e48871a04101cb23db304f24"}]},"branch":"refs/heads/master"},"8faa18ecc1126b4cd67926955e06d2170f589611":{"kind":"NO_CODE_CHANGE","_number":5,"created":"2025-11-10 21:34:27.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/83/966583/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/83/966583/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/83/966583/5"}}},"commit":{"parents":[{"commit":"c0a2c6b0bae01816b7da552fc1e1b83a8effe938","subject":"Merge \"fix ldap \u0027enabled\u0027 setting not interpreted as boolean\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c0a2c6b0bae01816b7da552fc1e1b83a8effe938"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2025-11-10 21:34:27.000000000","tz":0},"subject":"Invalidate token of user disabled in readonly backend","message":"Invalidate token of user disabled in readonly backend\n\nWe support custom identity plugins. They (and also LDAP backend) may be\nconsidered as a read-only (not supporting user data modification through\nKeystone API). When a user of such backend is disabled in the remote\nsystem Keystone will never learn about that and as such tokens for those\nusers will remain active. They cannot be renewed, but still they stay\nvalid.\nIn order to address this situation we need to do additional steps in the\ntoken validation and identify the current state of the user in the\nbackend. Due to the use of the token caching it is not possible to reuse\nnormal token validation functionality (it will never gets invalidated as\nsuch). In order to keep performance impact as low as possible modify the\ntoken validation as following:\n- regular checks\n- revocation check\n- if token is still active and revoke check passed fetch current user\n  data. When user is disabled - log a warning (explaining the situation)\n  and raise `UserDisabled` exception.\n\nSince Keystone also does not receive a message when user is reactivated\n(i.e. it was accidentally disabled) we cannot use the same approach as\nfor regular user disabling and generate a token revocation event. This\nwould cause the user to be locked out until the revocation event\nexpires.\n\nCloses-bug: #2122615\nChange-Id: If5b83feabc670ced54ef12fe7826267af7e3419d\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/8faa18ecc1126b4cd67926955e06d2170f589611"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/8faa18ecc1126b4cd67926955e06d2170f589611"}]},"branch":"refs/heads/master","description":"Edit commit message"},"543ef0a944cdfddf4902ba0330f9c8cfe8df56d9":{"kind":"REWORK","_number":6,"created":"2025-11-11 09:48:24.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/83/966583/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/83/966583/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/83/966583/6"}}},"commit":{"parents":[{"commit":"c0a2c6b0bae01816b7da552fc1e1b83a8effe938","subject":"Merge \"fix ldap \u0027enabled\u0027 setting not interpreted as boolean\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c0a2c6b0bae01816b7da552fc1e1b83a8effe938"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-11 09:48:09.000000000","tz":60},"subject":"Invalidate token of user disabled in readonly backend","message":"Invalidate token of user disabled in readonly backend\n\nWe support custom identity plugins. They (and also LDAP backend) may be\nconsidered as a read-only (not supporting user data modification through\nKeystone API). When a user of such backend is disabled in the remote\nsystem Keystone will never learn about that and as such tokens for those\nusers will remain active. They cannot be renewed, but still they stay\nvalid.\nIn order to address this situation we need to do additional steps in the\ntoken validation and identify the current state of the user in the\nbackend. Due to the use of the token caching it is not possible to reuse\nnormal token validation functionality (it will never gets invalidated as\nsuch). In order to keep performance impact as low as possible modify the\ntoken validation as following:\n- regular checks\n- revocation check\n- if token is still active and revoke check passed fetch current user\n  data. When user is disabled - log a warning (explaining the situation)\n  and raise `UserDisabled` exception.\n\nSince Keystone also does not receive a message when user is reactivated\n(i.e. it was accidentally disabled) we cannot use the same approach as\nfor regular user disabling and generate a token revocation event. This\nwould cause the user to be locked out until the revocation event\nexpires.\n\nCloses-bug: #2122615\nChange-Id: If5b83feabc670ced54ef12fe7826267af7e3419d\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/543ef0a944cdfddf4902ba0330f9c8cfe8df56d9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/543ef0a944cdfddf4902ba0330f9c8cfe8df56d9"}]},"branch":"refs/heads/master"},"c63efe1df102bcd6d39361bef45baf4ecdb7f1bd":{"kind":"REWORK","_number":7,"created":"2025-11-14 08:13:56.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/83/966583/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/83/966583/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/83/966583/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/83/966583/7"}}},"commit":{"parents":[{"commit":"c0a2c6b0bae01816b7da552fc1e1b83a8effe938","subject":"Merge \"fix ldap \u0027enabled\u0027 setting not interpreted as boolean\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c0a2c6b0bae01816b7da552fc1e1b83a8effe938"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-10 15:01:18.000000000","tz":60},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2025-11-14 08:13:49.000000000","tz":60},"subject":"Invalidate token of user disabled in readonly backend","message":"Invalidate token of user disabled in readonly backend\n\nWe support custom identity plugins. They (and also LDAP backend) may be\nconsidered as a read-only (not supporting user data modification through\nKeystone API). When a user of such backend is disabled in the remote\nsystem Keystone will never learn about that and as such tokens for those\nusers will remain active. They cannot be renewed, but still they stay\nvalid.\nIn order to address this situation we need to do additional steps in the\ntoken validation and identify the current state of the user in the\nbackend. Due to the use of the token caching it is not possible to reuse\nnormal token validation functionality (it will never gets invalidated as\nsuch). In order to keep performance impact as low as possible modify the\ntoken validation as following:\n- regular checks\n- revocation check\n- if token is still active and revoke check passed fetch current user\n  data. When user is disabled - log a warning (explaining the situation)\n  and raise `UserDisabled` exception.\n\nSince Keystone also does not receive a message when user is reactivated\n(i.e. it was accidentally disabled) we cannot use the same approach as\nfor regular user disabling and generate a token revocation event. This\nwould cause the user to be locked out until the revocation event\nexpires.\n\nCloses-bug: #2122615\nChange-Id: If5b83feabc670ced54ef12fe7826267af7e3419d\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c63efe1df102bcd6d39361bef45baf4ecdb7f1bd"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c63efe1df102bcd6d39361bef45baf4ecdb7f1bd"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
