)]}'
{"id":"openstack%2Fkeystone~990490","triplet_id":"openstack%2Fkeystone~stable%2F2026.1~Iaaa0ec713a0a5e062acc3209d6010982899d8f6f","project":"openstack/keystone","branch":"stable/2026.1","attention_set":{},"removed_from_attention_set":{"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-06-01 08:55:49.000000000","reason":"\u003cGERRIT_ACCOUNT_14250\u003e replied on the change","reason_account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}},"27900":{"account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"last_update":"2026-06-01 11:08:36.000000000","reason":"Change was submitted"}},"hashtags":["CVE-2026-43001"],"change_id":"Iaaa0ec713a0a5e062acc3209d6010982899d8f6f","subject":"Enforce delegation project boundary for delegated tokens","status":"MERGED","created":"2026-05-28 15:05:47.000000000","updated":"2026-06-01 11:10:57.000000000","submitted":"2026-06-01 11:08:36.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":1,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"990490","meta_rev_id":"50fdfe7a71a0d72e0fdc369669441f743301f61f","_number":990490,"virtual_id_number":990490,"owner":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-06-01 11:08:36.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"all":[{"value":2,"date":"2026-06-01 08:55:49.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2026-05-29 16:52:50.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"all":[{"value":1,"date":"2026-06-01 08:55:49.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-28 15:05:47.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"},{"updated":"2026-05-28 16:37:30.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"e760ea1c208a7fb25984b108278fa04c907dd833","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-05-28 15:05:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"1b158a70d8b0ec0d9d82eb3eb781cf3007a3fdf6","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 16:37:30.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/a5c04fa7a168402d8dc0646e425439fd\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/d0988ec94e1e41b58c24b768b1fecdc9 : SUCCESS in 15m 46s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/13c7ec0aa9b647a38114cc8635526818 : FAILURE in 5m 02s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/cae75a7175f24217a5f8ccce7d0e883b : SUCCESS in 11m 39s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/76f125a05bbd4a34bce0818bf87cf60b : SUCCESS in 7m 34s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/21352bfa12494213b10894f24f676057 : SUCCESS in 17m 12s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ef27ed22688d4682b2d81eb3d91bc232 : SUCCESS in 14m 58s\n- grenade https://zuul.opendev.org/t/openstack/build/ad46af2d1a424cf399cb43b5e4c056df : SUCCESS in 1h 04m 15s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/64a81e54dddc4763b0945810d73d8778 : SUCCESS in 1h 01m 29s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/33539347dc50483bb43d43241c930c00 : SUCCESS in 9m 59s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/8615f330f6c843eb8d3f460bebc1dcc4 : SUCCESS in 15m 20s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/8c5fd92bd3bb4053a584e12bb72fad0f : SUCCESS in 19m 36s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/356273ca48bd40209403a26a43e1e5f5 : FAILURE in 8m 05s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/a6a628e458574228a46b2fbfbbf3736c : FAILURE in 32m 26s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/896939ab432644f483794ec64fe446b4 : SUCCESS in 23m 40s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/d0015343957d478b96a98353203d9f52 : FAILURE in 33m 17s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/0d535c094e7a4b01ae6e85ccbdab00d4 : SUCCESS in 26m 21s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/c8840ef6773049fcb20517343dea6045 : SUCCESS in 35m 09s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/9c112f932e104ffebbb2d5ed7a6d1fd7 : SUCCESS in 23m 43s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/3e7abf94aef7435db79eac8cdd9bb685 : SUCCESS in 7m 48s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"215af21e75e71ff1c7451ee88906dbdb5e6ae9c9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-05-28 21:57:42.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"86b1cce58458607284bbb50bd02a0930a3d62363","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 23:56:47.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/a713e5117b9d47d8b68ec4b3f1ce910d\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/9015bd147c0f420b8a641c48fb78eda1 : SUCCESS in 20m 05s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/0c764be6ceaa4f20b41da8cbc64e2d2a : SUCCESS in 3m 23s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/f24a35ce5a3047889fe53c13c768638c : SUCCESS in 15m 13s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/5746b5bf77134c4396d573e48647ccd1 : SUCCESS in 11m 38s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/f5fbdb1787d64994a607184e25e6ce8e : SUCCESS in 17m 32s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/63e3a793106e4947a2c80553195066dd : SUCCESS in 13m 12s\n- grenade https://zuul.opendev.org/t/openstack/build/c74ad62d9924424da0da028765c01ab9 : SUCCESS in 1h 10m 21s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/84426b375b0a4082b8d5a2397b7de8e1 : SUCCESS in 1h 51m 15s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/2353a9a9776342b9bc2880d23bf0e5c8 : SUCCESS in 13m 06s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/d0d4e30f3f6e42839575e6a64ffd6dfe : SUCCESS in 9m 57s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/c7497cd3c7d041f898f85b61bb12c699 : SUCCESS in 32m 37s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/d37dde317a064fc0bc10d35df3f50c48 : FAILURE in 17m 47s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/0868391cf201433caac572b3a76dff52 : FAILURE in 15m 37s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/14988313001f4a1fb512492e7b144c38 : SUCCESS in 33m 46s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/2708e858be1e4d5d874a20060ea9f484 : FAILURE in 33m 01s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/65c07ba4450b47229050ea5c8e58a38f : SUCCESS in 35m 56s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/0c96e9d2b003437b97fa3b8a61f7f53c : SUCCESS in 36m 45s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/b96f4c10d14741ac8582c89a74dfb07c : FAILURE in 45m 45s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/b2e87d34fa724abc8794d438aa9707ee : SUCCESS in 4m 45s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"c140fb84b01e6fcd82f88ed449e122e1c4928365","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"date":"2026-05-29 06:39:09.000000000","message":"Hashtag added: CVE-2026-43001","accounts_in_message":[],"_revision_number":2},{"id":"8276778b610ee27b0e44f3941cfe42cebb3e06b1","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-05-29 15:29:12.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"8c8cb94b48648bccb55de582a5a80e5277416820","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-29 16:48:03.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2151e27df1674b0ebade7eee0cb48d5b\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/315806976f4d4f989803303b6dbce9ef : SUCCESS in 18m 32s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5a0b5add99b9484b9bdf0ce1b477f229 : SUCCESS in 7m 12s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/642d9c0c4a7c4ffea6a81e52207b0db2 : SUCCESS in 13m 33s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/67964fe7932247ec8a540bb316743956 : SUCCESS in 9m 52s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/16d3ad7235a14e97a3f3be8cfacf7b93 : SUCCESS in 13m 53s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/6087e79a489048eda0b8ddc10a73c3ee : SUCCESS in 9m 03s\n- grenade https://zuul.opendev.org/t/openstack/build/aa45920eb6ce4ec38636675a3fe122d0 : SUCCESS in 1h 06m 29s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/5ab2cebf816d49d5873a4d6a0b79be96 : SUCCESS in 1h 08m 48s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/73ca200e23204abfa7ded77e681f1ba1 : SUCCESS in 12m 10s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/3e9dd783cf69425d9a667d592939c81e : SUCCESS in 12m 09s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/f146509e87eb463f9d40a4e3340eeb48 : SUCCESS in 14m 45s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/c60d35b0dd86446cb2761d4c1678e70c : FAILURE in 11m 05s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/c269adf5c535475ba8bdb6bb2843ff48 : FAILURE in 26m 28s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/45cb6eb2be2743b9aebd116ba5dc05fb : SUCCESS in 30m 42s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/85a9e246fee044e2978a6194ff808f7e : SUCCESS in 15m 16s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/766af6b11cb84cf690cc3b1cb36f4d97 : SUCCESS in 26m 39s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/72652744ee634e289bcc1b91aa6288e4 : SUCCESS in 41m 00s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/ffb3925ea20e45e8a338efeccf23a021 : SUCCESS in 18m 55s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/6eac73dfdaa44df2b412fc2cac20c563 : SUCCESS in 6m 26s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"3907d2a05ed99033cb13f0fe773bd1337d9c7215","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-05-29 16:52:50.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"65adcb996891673efda42998251994029d2f04a2","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-06-01 08:55:49.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":2},{"id":"6051447661b627af8410b99f05b9de1beb48a8a4","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-01 08:56:36.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"1e8340ec0fedbc7c95cf48efbb4c7ef33e02882a","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-01 11:08:36.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/1a64b6349e754d2aa4a71eceb28e1e3a\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5aaeefd692bb4b8bb531536cded9e9ea : SUCCESS in 3m 50s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/4f71a6560fb54903abf26cd4d385ef2e : SUCCESS in 13m 03s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/b7ce9ad091e44cffb459e5a674edea6b : SUCCESS in 11m 02s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/59c0f0fb6a274cf089e188e34f90d6fc : SUCCESS in 15m 22s\n- grenade https://zuul.opendev.org/t/openstack/build/621204dfab334993a60360e29caf6d6d : SUCCESS in 42m 25s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/ddff58793260486ab7fc7b48516c1139 : SUCCESS in 1h 07m 06s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ea11d24176a5437dbbec2ef074cbd334 : SUCCESS in 12m 03s\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/ccaedef779ea4044b411c63a106175e9 : SUCCESS in 30m 46s\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/d859462399514ddeb251463463be1fd1 : SUCCESS in 35m 20s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/22572feb6348485ba25571fa278e4c69 : SUCCESS in 48m 42s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/e4d170ad54aa46e0abaae79ec59bafdf : SUCCESS in 31m 02s","accounts_in_message":[],"_revision_number":2},{"id":"e99aa7b16ed4f788bc1b5a852d3e1fec65033fb4","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-01 11:08:36.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"50fdfe7a71a0d72e0fdc369669441f743301f61f","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-01 11:10:57.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/e5b1d51c402a44ceb1f6f0ffb75fca10\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8bb4784f2cc54ed6b9a7204c0a716747 : SUCCESS in 1m 02s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/0765ba0137554635b63f0540b51443d2 : SUCCESS in 49s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"96fae039132da921a37d86d6a5a7b4e67d32d6f7","revisions":{"7459a4cc5627fa0c554d7a5b1c106ee4367fb477":{"kind":"REWORK","_number":1,"created":"2026-05-28 15:05:47.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/90/990490/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/90/990490/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/90/990490/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/90/990490/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/90/990490/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/90/990490/1"}}},"commit":{"parents":[{"commit":"635914a6a8a9fb3b172fc15528608df2d091036b","subject":"Block app cred tokens from authorizing OAuth1 requests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/635914a6a8a9fb3b172fc15528608df2d091036b"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-05-22 08:13:20.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n(cherry picked from commit 16582e5192be354e26ebef4badca1213ddc4dc07)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7459a4cc5627fa0c554d7a5b1c106ee4367fb477"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7459a4cc5627fa0c554d7a5b1c106ee4367fb477"}]},"branch":"refs/heads/stable/2026.1"},"96fae039132da921a37d86d6a5a7b4e67d32d6f7":{"kind":"REWORK","_number":2,"created":"2026-05-28 21:57:42.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/90/990490/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/90/990490/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/90/990490/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/90/990490/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/90/990490/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/90/990490/2"}}},"commit":{"parents":[{"commit":"635914a6a8a9fb3b172fc15528608df2d091036b","subject":"Block app cred tokens from authorizing OAuth1 requests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/635914a6a8a9fb3b172fc15528608df2d091036b"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-05-28 21:56:43.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n(cherry picked from commit 16582e5192be354e26ebef4badca1213ddc4dc07)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/96fae039132da921a37d86d6a5a7b4e67d32d6f7"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/96fae039132da921a37d86d6a5a7b4e67d32d6f7"}]},"branch":"refs/heads/stable/2026.1"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
