)]}'
{"id":"openstack%2Fkeystone~987120","triplet_id":"openstack%2Fkeystone~stable%2F2024.2~I9506557609ff7edaa6a961f356f9b8e19faaefc3","project":"openstack/keystone","branch":"stable/2024.2","attention_set":{},"removed_from_attention_set":{"13478":{"account":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"last_update":"2026-05-04 08:09:39.000000000","reason":"Change was abandoned"}},"hashtags":[],"change_id":"I9506557609ff7edaa6a961f356f9b8e19faaefc3","subject":"Block app cred tokens from authorizing OAuth1 requests","status":"ABANDONED","created":"2026-05-04 07:08:49.000000000","updated":"2026-05-04 08:09:39.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"7739849a357c9fba89cf39e44601003765dc59e8","_number":987120,"virtual_id_number":987120,"owner":{"_account_id":16137,"name":"Tobias Urdin","email":"tobias.urdin@binero.com","username":"tobasco"},"actions":{},"labels":{"Verified":{"all":[{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-04 07:08:49.000000000","updated_by":{"_account_id":16137,"name":"Tobias Urdin","email":"tobias.urdin@binero.com","username":"tobasco"},"reviewer":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"state":"REVIEWER"}],"messages":[{"id":"5af742d3aff15174e3382a36859fca7167224be7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":16137,"name":"Tobias Urdin","email":"tobias.urdin@binero.com","username":"tobasco"},"date":"2026-05-04 07:08:49.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"7739849a357c9fba89cf39e44601003765dc59e8","tag":"autogenerated:gerrit:abandon","author":{"_account_id":16137,"name":"Tobias Urdin","email":"tobias.urdin@binero.com","username":"tobasco"},"date":"2026-05-04 08:09:39.000000000","message":"Abandoned\n\ni must have missed that non-slurp goes directly into eol because i couldn\u0027t find the unmaintained branch","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"ec6851f2193cf2f8ba24687b931ffe551e151dc1","revisions":{"ec6851f2193cf2f8ba24687b931ffe551e151dc1":{"kind":"REWORK","_number":1,"created":"2026-05-04 07:08:49.000000000","uploader":{"_account_id":16137,"name":"Tobias Urdin","email":"tobias.urdin@binero.com","username":"tobasco"},"ref":"refs/changes/20/987120/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/20/987120/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/20/987120/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/20/987120/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/20/987120/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/20/987120/1"}}},"commit":{"parents":[{"commit":"3eaebcd536e67460f1ca4d15c1ec9ba32dff55e1","subject":"Block restricted app creds from creating EC2 credentials via /credentials","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/3eaebcd536e67460f1ca4d15c1ec9ba32dff55e1"}]}],"author":{"name":"Boris Bobrov","email":"b.bobrov@sap.com","date":"2026-04-07 21:55:23.000000000","tz":120},"committer":{"name":"Tobias Urdin","email":"tobias.urdin@binero.com","date":"2026-05-04 07:08:33.000000000","tz":120},"subject":"Block app cred tokens from authorizing OAuth1 requests","message":"Block app cred tokens from authorizing OAuth1 requests\n\nThe OAuth1 authorize endpoint checked is_delegated_auth to block\ntrust-scoped and OAuth-scoped tokens from authorizing request\ntokens, but application credential tokens were not covered by\nthis check. A restricted application credential could authorize\na request token with any role the user actually holds, producing\nan access token that yields an unrestricted Keystone token with\nroles beyond the application credential\u0027s restricted set.\n\nAdd an explicit check for application credential tokens on the\nOAuth1 authorize endpoint, consistent with how trust-scoped and\nOAuth-scoped tokens are already blocked.\n\nRelated-Bug: #2142138\nGenerated-By: claude-opus-4-6 (OpenCode)\nSigned-off-by: Boris Bobrov \u003cb.bobrov@sap.com\u003e\nChange-Id: I9506557609ff7edaa6a961f356f9b8e19faaefc3\n(cherry picked from commit 29246c5fd8d1dafbe6cc8cec4c57faf5590cd44e)\n(cherry picked from commit 33744fef63a618e074af4915f03427a054ac4bc8)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/ec6851f2193cf2f8ba24687b931ffe551e151dc1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/ec6851f2193cf2f8ba24687b931ffe551e151dc1"}]},"branch":"refs/heads/stable/2024.2"}},"requirements":[],"submit_records":[],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
