)]}'
{"id":"openstack%2Fkeystone~990485","triplet_id":"openstack%2Fkeystone~master~Iaaa0ec713a0a5e062acc3209d6010982899d8f6f","project":"openstack/keystone","branch":"master","topic":"review/990485","attention_set":{},"removed_from_attention_set":{"7973":{"account":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"last_update":"2026-05-28 21:18:54.000000000","reason":"Change was marked work in progress"},"7414":{"account":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"last_update":"2026-05-28 21:18:54.000000000","reason":"Change was marked work in progress"},"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-05-29 17:34:10.000000000","reason":"Change was submitted"},"27900":{"account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"last_update":"2026-05-29 17:34:10.000000000","reason":"Change was submitted"}},"hashtags":["CVE-2026-43001"],"change_id":"Iaaa0ec713a0a5e062acc3209d6010982899d8f6f","subject":"Enforce delegation project boundary for delegated tokens","status":"MERGED","created":"2026-05-28 15:05:16.000000000","updated":"2026-05-29 17:35:52.000000000","submitted":"2026-05-29 17:34:10.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":2,"unresolved_comment_count":1,"has_review_started":true,"submission_id":"990485-review/990485","meta_rev_id":"adc8bf059d502c96670df64796ef8b66e14eeadb","_number":990485,"virtual_id_number":990485,"owner":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-05-29 17:34:10.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":2,"date":"2026-05-29 15:11:25.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2026-05-29 12:35:53.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":1,"date":"2026-05-29 15:11:25.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}],"reviewers":{"REVIEWER":[{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"CC":[{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-28 15:05:16.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"},{"updated":"2026-05-28 15:59:44.000000000","updated_by":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"reviewer":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"state":"CC"},{"updated":"2026-05-28 16:02:40.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"CC"},{"updated":"2026-05-28 17:48:37.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2026-05-28 17:57:10.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-05-28 19:41:49.000000000","updated_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"},{"updated":"2026-05-28 20:06:26.000000000","updated_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"reviewer":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"state":"REVIEWER"},{"updated":"2026-05-28 20:06:26.000000000","updated_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"reviewer":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"state":"REVIEWER"}],"messages":[{"id":"9f01f3ed94d53e7eac41853e982104f6ba663719","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-05-28 15:05:16.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"e38bed21c7a66a8a2381e92d9903c4ae34925d54","author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"date":"2026-05-28 15:59:44.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"3ee7cc7ac3f3fec6e1cb0a33ab4d87adbf9cc32c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-05-28 16:02:40.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"9f7b51245cde01b7ef131d056e64d845656e8400","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 17:48:37.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/de1b5017347848e8aa7652804c0ca0ef\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/5de4694ae54b465a8f2e0c1b8b87644c : SUCCESS in 14m 10s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/16a70f6f0d4b4bfc93266ca72209585f : NODE_FAILURE Node(set) request 57cf29a0310e415883febba09f8ba4b7 failed in 0s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/1c7e29e2c3554ea5a8e76ac3b701c19e : NODE_FAILURE Node(set) request ee6488d0dd614b928c4f7bc0956f666c failed in 0s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"645ba5ea714898a44a54f06e4c3efd0a1891211e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 17:57:10.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/2fa156d4a16343a8830608071ad960a1\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f1c47d9fbb30457a89f3fa7200b843df : SUCCESS in 21m 57s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/efa17d931e8d496e8107bc71a7f28ee1 : FAILURE in 5m 06s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/e87d20428d8542c4a80455d8ebf418df : SUCCESS in 7m 13s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/a8d75c0cbc1341f3916557840fb639a4 : SUCCESS in 8m 28s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/4de991c75ecb432f8870254000077306 : SUCCESS in 8m 53s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4a0c3faeb6be40d493590bc2920daa72 : SUCCESS in 7m 34s\n- grenade https://zuul.opendev.org/t/openstack/build/218deac99bc6413280f540493d107098 : SUCCESS in 33m 36s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/22894a36714b4af19d129ee805e95515 : SUCCESS in 1h 53m 16s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/a7dce6b81fe64118bb9fb3c2fc6a1056 : SUCCESS in 12m 33s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/c7d265e36deb4d3f85ea3059ce861488 : SUCCESS in 17m 40s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/51feec6dbbdc4982ba8782ef7199b700 : SUCCESS in 38m 09s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/e5918319fcc04e8fb055b2ea0ed28401 : FAILURE in 19m 02s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/30c33e5088094a04bf7cfa8b3f23b1c2 : FAILURE in 14m 25s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/962cc3cef6b1477eb50f08b5aa973b65 : SUCCESS in 31m 23s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/21fba67eca094fe38f0370b6ff48d331 : FAILURE in 35m 05s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/618c09bede144553a29b15e2439ad97c : SUCCESS in 20m 07s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/8fed5b7321c1434281b83f2c31f04460 : SUCCESS in 33m 39s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/2faee7f97f16466fb1e482a3651cc3b2 : SUCCESS in 20m 30s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/62a276165ba64e1699b05604b0268c4f : SUCCESS in 8m 30s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"a703889fc112855268e46628c4aa352eaadca03f","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-05-28 19:41:49.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":3},{"id":"f5e3f2c1fc81bba5bffa706773078df401a23d10","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-05-28 20:06:26.000000000","message":"Patch Set 3:\n\nThis change is ready for review.","accounts_in_message":[],"_revision_number":3},{"id":"bb3eb1b8bcec397ed77f3c97fe1293ddcde44bca","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-05-28 21:18:54.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"2a7f0899e316028b204de7a51dcd79661adb6092","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-05-28 21:20:19.000000000","message":"Patch Set 4:\n\nThis change is ready for review.","accounts_in_message":[],"_revision_number":4},{"id":"66d115dd6fff56c735c9874988fe30e4ecedd71e","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 22:49:18.000000000","message":"Patch Set 4:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/02529c397e57475d9991c52a8032852d\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/94a7393e817f4bde8deb7addeb1f1882 : SUCCESS in 29m 40s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/3e50a5b6e1364b5db31e580ce6149767 : SUCCESS in 21m 51s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/7ce2f93a5f864cdda0b14a4703c63739 : SUCCESS in 32m 17s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"903566d50cd579a1e48254f9891a7711525f004b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 23:10:30.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/b472e2bac090437b94883bed0afbe368\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/3780ec2a55de417b8b393822f911780f : SUCCESS in 18m 57s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e12789f5f6354a498a633ef05e5ed654 : SUCCESS in 3m 24s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/945c84c6de11487ebfd6f46c73f268dc : SUCCESS in 11m 27s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/67a3c694d8ff46d3823f765f90b4fd8c : SUCCESS in 11m 09s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/24031324b76e4b14aea279ee976fb2d7 : SUCCESS in 15m 00s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f77402b6c6af4f8e9e02aac771bde99f : SUCCESS in 13m 02s\n- grenade https://zuul.opendev.org/t/openstack/build/72403eee88f84ab685d6f1b180d4d7e4 : SUCCESS in 1h 02m 07s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/e4fb1df6b2824ba880b565069cc3d0b8 : SUCCESS in 1h 41m 44s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/72cdf73ac10f4425a84d549acd05cbac : SUCCESS in 5m 01s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/205d0eb3d76548c9975d07b5f0e04c38 : SUCCESS in 18m 43s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/01e4cb51786b46db8cb9101fbad63b81 : SUCCESS in 33m 32s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/2d531b6549d94bf3912dbc9f2d80b689 : FAILURE in 18m 59s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/6f64b8e8c1dd49f3b4e782de904533b0 : FAILURE in 12m 53s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/b19e82472af7423eba6ae27046c0ea22 : SUCCESS in 31m 21s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/7c869ae71f78467081a509ab98c5ddfe : FAILURE in 30m 10s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/e06e8be761184f6fadbb5deb6597ae18 : SUCCESS in 36m 11s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/6b02508fd5f9408d9c842103640d5b96 : SUCCESS in 1h 02m 36s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/96dbf066d181442f93c2b7333af97de2 : SUCCESS in 31m 03s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/31f18395fbf44079b6b6616e850eee91 : SUCCESS in 7m 39s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"e364d0a82aab0bd1b9b5dabb033eb1146cf03d50","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"date":"2026-05-29 06:39:08.000000000","message":"Hashtag added: CVE-2026-43001","accounts_in_message":[],"_revision_number":4},{"id":"0048494168fe475f4ccfc18e55eb4852a73a5853","author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"date":"2026-05-29 09:59:20.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"7ad7a4d20f1d2f27a3c6d87e84221cb92f6341e8","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-29 11:28:12.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/5b4dc2760b2347138a08512d11c3f7ab\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/320ea0b00a52466d925668165383beb1 : SUCCESS in 10m 57s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a33c544c693048268b829a8aaa8eafa0 : SUCCESS in 5m 01s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/acb1f0eeb9b44328964e4a275deeca6f : SUCCESS in 7m 10s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/ab39f47bb2c2414eb0fc004462122bb4 : SUCCESS in 7m 15s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/46d127ce2c4a4462abbae60b0cd1fe09 : SUCCESS in 9m 19s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ba6004c6ac974a299c818a5f8afc3bd6 : SUCCESS in 12m 23s\n- grenade https://zuul.opendev.org/t/openstack/build/f24e18d2f0674bf6956a2e6ee2983ece : SUCCESS in 1h 09m 31s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/efe069270822436396db2f5883d5103f : SUCCESS in 1h 27m 39s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/12b2ddec555645b1af371bbed50ea011 : SUCCESS in 9m 21s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/db3113313eff47a39e468f7c06c608ec : SUCCESS in 8m 56s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/972e091880b34d968c883475c177fc15 : SUCCESS in 22m 05s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/53a6f30cb4764a5185ab0d32098a1b5f : FAILURE in 20m 11s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/fc2146167b704beca7ad8ae7a30fe1a4 : FAILURE in 28m 11s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/48d10c6ff8a54fde989a5d57f9e03f1b : SUCCESS in 31m 20s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/2796070d80e74531b2e30c2c7419cbea : SUCCESS in 35m 21s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/54083b6083a24e11b037fac4b3d9aa93 : SUCCESS in 26m 29s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/1a711455027c45b18d6e33d8c2937a2f : SUCCESS in 1h 00m 45s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/b11ec4a70fad4e9a892021e0e512cd2b : SUCCESS in 18m 57s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/bef954bb8b3d4f25a5fb4997a0398ae5 : SUCCESS in 8m 02s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"f8719aee48ed7d10fa41f4fab1443fb93a8500e8","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-29 12:15:00.000000000","message":"Patch Set 4:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/7105d6258ce04a99a13c67d8653c4f77\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/2c8150171a65424d89df38f6661a9f7c : SUCCESS in 17m 30s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/f6b910633e58466c89dc948b1bb4524e : SUCCESS in 22m 58s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/06199995e2dc4601a45a6b75c339093c : SUCCESS in 21m 49s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"d28780ebe3274eca9310283b09b7c67f969b65f0","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-05-29 12:35:53.000000000","message":"Patch Set 4: Code-Review+2","accounts_in_message":[],"_revision_number":4},{"id":"53641f7c7932a66ed087d08bfc6c063a3410f725","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-29 15:11:25.000000000","message":"Patch Set 4: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":4},{"id":"3efc0af280e3abe9e39996bb22ec418ac5da055a","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-29 15:12:05.000000000","message":"Patch Set 4: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":4},{"id":"5b4c2e35d4b7b277d6dbf04f585b6fffe02a31ad","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-29 17:34:10.000000000","message":"Patch Set 4: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/3fe423f62d614b889b6dabfb95ba7dce\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/c3a581b3813447c1a9bb9641b35f288e : SUCCESS in 3m 25s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/22bca27214394571b2bb81f8da0811f0 : SUCCESS in 10m 03s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/34fcc946a4be4aadbb1c9ccc7f0e034b : SUCCESS in 9m 41s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c2df95b38c8b48c4bcd146912bf7df1b : SUCCESS in 13m 17s\n- grenade https://zuul.opendev.org/t/openstack/build/0dce84b433a84b96991388229631a8d5 : SUCCESS in 1h 08m 11s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/1754df05021e46a18b3d41f8ac7fca2d : SUCCESS in 1h 53m 50s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/6fc58ec008e94a3489e1f8000990dfa6 : SUCCESS in 7m 40s\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/8fdf53ca69b246efa01765aa1afeba04 : SUCCESS in 30m 57s\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/69672a6f95d7439281f2017f7b9084e0 : SUCCESS in 30m 18s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/68e546824ce540388f0170589d4cddbe : SUCCESS in 46m 37s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/76611335a91c4b05b8a35cf4fa913462 : SUCCESS in 44m 30s","accounts_in_message":[],"_revision_number":4},{"id":"f4a68ef4234a78bc03d96ba0d74b000688141a61","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-29 17:34:10.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":4},{"id":"adc8bf059d502c96670df64796ef8b66e14eeadb","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-29 17:35:52.000000000","message":"Patch Set 4:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/7f2fcac3595749b8914ad96d1114bb75\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/88d3de450f8941ed9bed3c80aad37ec1 : SUCCESS in 1m 14s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/e64055b6a89242bfbf27231d4f313b95 : SUCCESS in 1m 06s","accounts_in_message":[],"_revision_number":4}],"current_revision_number":4,"current_revision":"f82b093507495227c648df6a9b20cbc18f0cb474","revisions":{"780b0a4742a90da8eff2d6c33ab7d8435109ffb9":{"kind":"REWORK","_number":1,"created":"2026-05-28 15:05:16.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/85/990485/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/85/990485/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/85/990485/1"}}},"commit":{"parents":[{"commit":"2230026f77a8ed50493d2d58be9120910ceb2089","subject":"Merge \"Fix keystone scope flag in tempest.conf\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2230026f77a8ed50493d2d58be9120910ceb2089"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-05-22 08:08:11.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/780b0a4742a90da8eff2d6c33ab7d8435109ffb9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/780b0a4742a90da8eff2d6c33ab7d8435109ffb9"}]},"branch":"refs/heads/master"},"bd5082acf6a961774177d54ecb53c3868dc48f39":{"kind":"REWORK","_number":2,"created":"2026-05-28 16:02:40.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/85/990485/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/85/990485/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/85/990485/2"}}},"commit":{"parents":[{"commit":"2230026f77a8ed50493d2d58be9120910ceb2089","subject":"Merge \"Fix keystone scope flag in tempest.conf\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2230026f77a8ed50493d2d58be9120910ceb2089"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-05-28 16:01:49.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/bd5082acf6a961774177d54ecb53c3868dc48f39"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/bd5082acf6a961774177d54ecb53c3868dc48f39"}]},"branch":"refs/heads/master"},"609fe2e3bc95dd2e43469f3a5f4cd9bf2b2da663":{"kind":"REWORK","_number":3,"created":"2026-05-28 19:41:49.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/85/990485/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/85/990485/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/85/990485/3"}}},"commit":{"parents":[{"commit":"2230026f77a8ed50493d2d58be9120910ceb2089","subject":"Merge \"Fix keystone scope flag in tempest.conf\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2230026f77a8ed50493d2d58be9120910ceb2089"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-05-28 19:40:18.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/609fe2e3bc95dd2e43469f3a5f4cd9bf2b2da663"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/609fe2e3bc95dd2e43469f3a5f4cd9bf2b2da663"}]},"branch":"refs/heads/master"},"f82b093507495227c648df6a9b20cbc18f0cb474":{"kind":"REWORK","_number":4,"created":"2026-05-28 21:18:54.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/85/990485/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/85/990485/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/85/990485/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/85/990485/4"}}},"commit":{"parents":[{"commit":"2230026f77a8ed50493d2d58be9120910ceb2089","subject":"Merge \"Fix keystone scope flag in tempest.conf\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2230026f77a8ed50493d2d58be9120910ceb2089"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-05-28 21:18:42.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/f82b093507495227c648df6a9b20cbc18f0cb474"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/f82b093507495227c648df6a9b20cbc18f0cb474"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
