)]}'
{"id":"openstack%2Fkeystone~982029","triplet_id":"openstack%2Fkeystone~master~Ib84f258bb653327c778881198de1e2aec8a3427d","project":"openstack/keystone","branch":"master","hashtags":[],"change_id":"Ib84f258bb653327c778881198de1e2aec8a3427d","subject":"Update last_active_at on app cred auth","status":"ABANDONED","created":"2026-03-25 00:28:45.000000000","updated":"2026-03-25 00:29:28.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"971ff340377fd9800c9aca116b534add9e5b3c82","_number":982029,"virtual_id_number":982029,"owner":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"actions":{},"labels":{"Verified":{"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{},"pending_reviewers":{},"reviewer_updates":[],"messages":[{"id":"fab1db4c8bdd9cdb079906be69bf283d12799f3d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"date":"2026-03-25 00:28:45.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"971ff340377fd9800c9aca116b534add9e5b3c82","tag":"autogenerated:gerrit:abandon","author":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"date":"2026-03-25 00:29:28.000000000","message":"Abandoned\n\nthere is another change already","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"143cf4b5f98bc949b75d1e08e12f9fa032208b93","revisions":{"143cf4b5f98bc949b75d1e08e12f9fa032208b93":{"kind":"REWORK","_number":1,"created":"2026-03-25 00:28:45.000000000","uploader":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"ref":"refs/changes/29/982029/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/29/982029/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/29/982029/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/29/982029/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/29/982029/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/29/982029/1"}}},"commit":{"parents":[{"commit":"2f5085676a305773ad6012e1819fa21931634988","subject":"Merge \"api-ref: add missing enabled field on endpoint\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2f5085676a305773ad6012e1819fa21931634988"}]}],"author":{"name":"Boris Bobrov","email":"b.bobrov@sap.com","date":"2026-03-09 22:22:00.000000000","tz":60},"committer":{"name":"Boris Bobrov","email":"b.bobrov@sap.com","date":"2026-03-24 21:52:18.000000000","tz":60},"subject":"Update last_active_at on app cred auth","message":"Update last_active_at on app cred auth\n\nThe application credential auth plugin did not update the user\u0027s\nlast_active_at timestamp on successful authentication. This caused\nusers who exclusively authenticate via application credentials to\nbe incorrectly disabled when the disable_user_account_days_inactive\nsecurity compliance option was configured, because Keystone\nconsidered them inactive despite active application credential\nusage.\n\nThe root cause was that only the password auth plugin (via\nidentity_api.authenticate()) and federated auth (via\n_shadow_nonlocal_user()) called set_last_active_at, while the\napplication credential plugin used a separate code path through\napplication_credential_api.authenticate() that never updated the\nuser\u0027s last active timestamp.\n\nAdd a call to shadow_users_api.set_last_active_at() in the\napplication credential auth plugin after successful credential\nvalidation, gated behind a new [application_credential]\ntrack_last_active_at config option (default True). This allows\noperators who want application credential usage to NOT count as\nuser activity (e.g. for strict rotation policies) to disable\nthe behavior.\n\nCloses-Bug: #2117217\nGenerated-By: claude-opus-4-6 (OpenCode)\nSigned-off-by: Boris Bobrov \u003cb.bobrov@sap.com\u003e\nChange-Id: Ib84f258bb653327c778881198de1e2aec8a3427d\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/143cf4b5f98bc949b75d1e08e12f9fa032208b93"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/143cf4b5f98bc949b75d1e08e12f9fa032208b93"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
