)]}'
{"id":"openstack%2Fkeystone~990495","triplet_id":"openstack%2Fkeystone~stable%2F2025.2~Iaaa0ec713a0a5e062acc3209d6010982899d8f6f","project":"openstack/keystone","branch":"stable/2025.2","attention_set":{},"removed_from_attention_set":{"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-06-08 18:34:55.000000000","reason":"Change was submitted"},"27900":{"account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"last_update":"2026-06-08 16:56:05.000000000","reason":"\u003cGERRIT_ACCOUNT_27900\u003e replied on the change","reason_account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}}},"hashtags":["CVE-2026-43001"],"change_id":"Iaaa0ec713a0a5e062acc3209d6010982899d8f6f","subject":"Enforce delegation project boundary for delegated tokens","status":"MERGED","created":"2026-05-28 15:06:15.000000000","updated":"2026-06-08 18:37:35.000000000","submitted":"2026-06-08 18:34:55.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":1,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"990495","meta_rev_id":"3212a4091f9733687bd5ae7b454c988de35ea6c6","_number":990495,"virtual_id_number":990495,"owner":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-06-08 18:34:55.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"all":[{"value":2,"date":"2026-06-03 12:05:51.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":2,"date":"2026-06-08 16:56:05.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"all":[{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":1,"date":"2026-06-08 16:56:05.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-28 15:06:15.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"},{"updated":"2026-05-28 16:51:44.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"b51cce3723ff289f7caaf2914fe6582dbb5e5a9d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-05-28 15:06:15.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"ee6860af4a45069ae34429b53ff83237a67abb32","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 16:51:44.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/a07ab4353fb540eb97b6e9d4cc04cffc\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/95c4c28a6ac74f9aaf0ddf4852fa0be1 : SUCCESS in 17m 01s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/88b0c5778af34508b731062e4d5ea677 : FAILURE in 5m 39s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/42cb512a03804ce0aff73f7e541bb173 : SUCCESS in 8m 38s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/bcfeff064c11466c8a03686334807c72 : SUCCESS in 15m 31s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/d94f632ca97e40e58d143e6e581831f4 : SUCCESS in 16m 15s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/97bd7e497f634ca0aff054565f5eaf75 : SUCCESS in 8m 08s\n- grenade https://zuul.opendev.org/t/openstack/build/f1174ae75cfd4200bbc37cbff4d585a3 : SUCCESS in 1h 03m 44s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/b1bd1bd765284d6cbf2a0d1a51728995 : SUCCESS in 1h 36m 31s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/0da1fa120c5d4da18ba43b65b5e71ea5 : SUCCESS in 12m 36s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/75df0c9846ce4ddc91122a11ad35d137 : SUCCESS in 24m 40s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/4f9b2ac87ec04612ae987ae522988fde : SUCCESS in 14m 28s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/40275ee1207e4830864483fea3737f7e : FAILURE in 12m 21s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/24eeeca7f4e74024a3b0fb6f1649c143 : FAILURE in 22m 33s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/aeb2315b4942498780b24a88e537910b : FAILURE in 21m 06s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/964a18945fbd41afaf37d10c64217610 : FAILURE in 34m 24s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/8cf2f0f5c69d4e9180c41af2b29b28b9 : SUCCESS in 20m 25s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/0bcabe49bb0d4e409ae9d61924578af2 : SUCCESS in 56m 20s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/ef9c47814dcb473a95beda1e49d8a1fd : FAILURE in 40m 32s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/37d7cb199cb34b999d0674824555fb80 : FAILURE in 8m 23s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"c5d0965e1d62c8d9beb32abadd843ee606a01b14","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-05-28 21:58:04.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"c269ec9a0bb04bdcf044b30e7a971d764028e8e7","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-28 23:22:28.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/ab75c2c770b345c8a926698cb7da3ed0\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/8b6ecc294a2848288d30af89b634db3c : SUCCESS in 17m 01s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/24c28b6f6fc547b09fb7e5607b307f82 : SUCCESS in 6m 39s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/97d115a16cb04c119bb7a1aed8cced3a : SUCCESS in 14m 01s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/243bc01b11164bd5b0cb3c26cfad1e6f : SUCCESS in 13m 32s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/4be4f9e461c348059a48332f49681f14 : FAILURE in 17m 09s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/653ee4f14bdf433badc3ebcd7220c34e : SUCCESS in 14m 19s\n- grenade https://zuul.opendev.org/t/openstack/build/378d3ed02a3f45e7845ecee278e4549d : SUCCESS in 1h 17m 37s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/ddf2d3450d3741648139df94fdbea4fb : SUCCESS in 1h 00m 00s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/e57bb38933414f55b59bdd6cc26b934d : SUCCESS in 10m 44s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/65794b77f97d4a7dafd6b2f7720c5c6e : SUCCESS in 20m 41s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/4d2e68aa290d4773b7d6fa6e7f830998 : SUCCESS in 16m 08s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/be422800cc1947778ffb0cb3b49d1428 : FAILURE in 8m 13s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/1f2cc07fd15b41b6b1cec87890b3e87b : FAILURE in 17m 41s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/08415eea787841ba928214971cec958c : FAILURE in 14m 42s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/6b1f6b73e7504d3eaa1e47be63935652 : FAILURE in 31m 54s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/2b36291b96b3402e820701d4446f1bc1 : SUCCESS in 27m 53s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/de2c1a18e08646dd9faba4ef8fbf8828 : SUCCESS in 1h 02m 41s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/6c29f3f3e9bf416fa26fe45f0b9e1242 : FAILURE in 32m 01s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/3092c674349a44dc9dbdca52669f4f03 : FAILURE in 8m 07s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"065019b6585b314380e56bd0a7b93f4657c59e2e","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"date":"2026-05-29 06:39:09.000000000","message":"Hashtag added: CVE-2026-43001","accounts_in_message":[],"_revision_number":2},{"id":"165751835d20ae4136e10d5f86bedbdfe31022df","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-06-03 12:05:16.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"3fd71398b40171a78be22d0d3df9592b3f08c2fc","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-06-03 12:05:51.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"27d9f2fe1649642142fc97e74d7426ede3822d8d","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-03 14:21:54.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2d68ec26601d48fd91443cfe77f6401e\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/41ebfad84ada49e9a83cb6cd42cc0812 : SUCCESS in 17m 33s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/6adaa8dc8de342abb18de2970e9a399b : SUCCESS in 7m 09s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/fa010473235240fbbbe46a2224f196bc : SUCCESS in 14m 43s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/dd5a1cfc29ab4ca58059acb5dc479896 : SUCCESS in 13m 21s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/f0eccb69f72740a68495b367e3385fce : SUCCESS in 17m 31s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c321e85b3c3b46c480d932216b6f7a5f : SUCCESS in 13m 11s\n- grenade https://zuul.opendev.org/t/openstack/build/fabfd573bab346b49d8b050dcac40ba2 : SUCCESS in 31m 48s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/7b2be5c49a874766bd386b66feae8b77 : SUCCESS in 2h 02m 05s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/25e813ee147a49e195231a74f21d98dc : SUCCESS in 5m 58s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/ca54e8a0366f46d6a77bb1a678bc1204 : SUCCESS in 8m 38s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/2989e445cc374f82961ae4efb0a13b5d : SUCCESS in 29m 49s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/7dca5aa359044aa9a8670ebcf92a2225 : FAILURE in 9m 47s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/4c2b2d4356c8418cb8c67e70028c2885 : FAILURE in 33m 05s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/c02a89c1f44244a6b686ebe34323ddea : SUCCESS in 18m 54s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/e683f44ba23046b0b32e6fa8d6d8935b : SUCCESS in 32m 48s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/af0da3ae0fc34afbb3de1c482fc9ce36 : FAILURE in 9m 37s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/bbc20a95378e4c4b8322a4f95eb00970 : SUCCESS in 59m 29s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/f8b20b19ec4a4125929c03cb857d9757 : SUCCESS in 20m 06s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/2ef408c8ffe9499a8e5ca0d365523e56 : FAILURE in 5m 49s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"6da5542ed9e176cacb9703107559071cd8ed2700","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-06-08 16:56:05.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":2},{"id":"e224c2d8b8026f25bd31cc5a504747356787c96f","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-08 16:57:16.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"b877ae7ee75c8b73ba599f18d1f405f188ae4154","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-08 18:34:55.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/9308684c76de476caaeddbb2f13398cc\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e56397e35b614afca7cf5f3e908e341f : SUCCESS in 10m 15s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/4ea4dbdf5f194163ba542bcbcd4a4bd6 : SUCCESS in 13m 38s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/7c8a4bdbac044b67b4d56f7a6d7f8f4b : SUCCESS in 8m 44s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f23653eb61644e60bc9e9f5904a19ab4 : SUCCESS in 15m 33s\n- grenade https://zuul.opendev.org/t/openstack/build/672c5b627b964ef2a244fed68bbbbac5 : SUCCESS in 1h 01m 45s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/b3271e3078b14dcab51960736672901e : SUCCESS in 1h 06m 28s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/39d536b661844649bc0f0fa102bd48c2 : SUCCESS in 8m 25s\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/f579e790e8554f5a802fe818c29b5ab8 : SUCCESS in 14m 19s\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/115bb2bc1cf84c14ad69997ee63d5cf1 : SUCCESS in 31m 24s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/ac4824c7a7be4642a7920032f637cebb : SUCCESS in 52m 56s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/bce4dd752a1e4ef29a1cd57098d15f98 : SUCCESS in 19m 04s","accounts_in_message":[],"_revision_number":2},{"id":"ac58cb6603d0c4a24e0011c30f2d58157a2149b7","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-08 18:34:55.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"3212a4091f9733687bd5ae7b454c988de35ea6c6","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-08 18:37:35.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/05099486089b4b93aeb481fb2f534c40\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4703b9ff0f794c6dbcf992c31a180125 : SUCCESS in 1m 07s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/c46afe53aa6c49969b3da8ab6bd0bc44 : SUCCESS in 44s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"fda177eb5a94ad6377fa912e44c90a3ccdb67f16","revisions":{"a1f67825be712985a056a97952434a9ec089f799":{"kind":"REWORK","_number":1,"created":"2026-05-28 15:06:15.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/95/990495/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/95/990495/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/95/990495/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/95/990495/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/95/990495/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/95/990495/1"}}},"commit":{"parents":[{"commit":"b433d009eaa6287f398cbca27e97c01cac77de58","subject":"Merge \"Enforce app cred project boundary on EC2 credential paths\" into stable/2025.2","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b433d009eaa6287f398cbca27e97c01cac77de58"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-05-22 08:18:41.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n(cherry picked from commit 16582e5192be354e26ebef4badca1213ddc4dc07)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a1f67825be712985a056a97952434a9ec089f799"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a1f67825be712985a056a97952434a9ec089f799"}]},"branch":"refs/heads/stable/2025.2"},"fda177eb5a94ad6377fa912e44c90a3ccdb67f16":{"kind":"REWORK","_number":2,"created":"2026-05-28 21:58:04.000000000","uploader":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"ref":"refs/changes/95/990495/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/95/990495/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/95/990495/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/95/990495/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/95/990495/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/95/990495/2"}}},"commit":{"parents":[{"commit":"b433d009eaa6287f398cbca27e97c01cac77de58","subject":"Merge \"Enforce app cred project boundary on EC2 credential paths\" into stable/2025.2","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b433d009eaa6287f398cbca27e97c01cac77de58"}]}],"author":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-04-23 08:13:20.000000000","tz":120},"committer":{"name":"Grzegorz Grasza","email":"xek@redhat.com","date":"2026-05-28 21:56:58.000000000","tz":120},"subject":"Enforce delegation project boundary for delegated tokens","message":"Enforce delegation project boundary for delegated tokens\n\nDelegated tokens (trusts, application credentials, OAuth1 access tokens)\nare scoped to a single project at delegation time. This must be enforced\nthoroughly while granting the API access to Keystone resources that\nmight be also bound to a single project. Without this it is possible to\ngain different access (using trust to see application credentials for a\ndifferent project, reuse the MFA seed, etc).\n\n* Credentials CRUD (/v3/credentials)\n\n  All five CRUD operations verified ownership via user_id but did not bind\n  credential.project_id to the delegating token\u0027s project scope.\n\n  Fix: _check_credential_project_scope() - no-op for non-delegated tokens,\n  raises ForbiddenAction on project mismatch. For list, out-of-scope\n  credentials are silently filtered.\n\n  Credentials with project_id\u003dNone (TOTP/MFA bindings) are treated as\n  out-of-scope for any delegated token: they are user-level secrets with no\n  project anchor, and a delegated token should never be able to enumerate,\n  read, or mutate them - doing so would allow a stolen delegation token to\n  exfiltrate or destroy a user\u0027s MFA binding.\n\n* OS-EC2 credential CRUD (/v3/users/{id}/credentials/OS-EC2)\n\n  POST accepted any tenant_id from a delegated token. GET and DELETE had\n  no delegation check at all.\n\n  Fix: _check_delegation_for_ec2() enforces the project boundary;\n  list silently filters.\n\n  Additionally, pre-existing OAuth1 access-token-backed EC2 credentials\n  with a mismatched project_id could be used at auth-time (POST /v3/ec2tokens)\n  to obtain a cross-project token. Added a check in EC2_S3_Resource.py that\n  cred_data[\u0027project_id\u0027] matches access_token[\u0027project_id\u0027] before issuing\n  the token. The trust branch does not need this check - the token provider\n  uses the trust\u0027s project regardless of the credential\u0027s project_id.\n\n* OS-OAUTH1 access token management (/v3/users/{id}/OS-OAUTH1/access_tokens)\n\n  GET and DELETE had no delegation check. List blocked trust/OAuth but not\n  app-cred tokens.\n\n  Fix: _block_delegated_token() raises Forbidden for any delegation type\n  on list, get, and delete.\n\n* Application credential management (/v3/users/{id}/application_credentials)\n\n  Trust-scoped and OAuth1 tokens had no guard on the application credential\n  and access rule management APIs. An impersonating trust could LIST, CREATE,\n  or DELETE application credentials, creating a persistent backdoor that\n  outlives the trust\u0027s own expiry. App credential tokens are intentionally\n  excluded - the unrestricted/restricted distinction is handled separately by\n  _check_unrestricted_application_credential.\n\n  Fix: _block_delegated_token_app_creds() raises Forbidden for trust-scoped\n  and OAuth1 tokens on all six app credential and access rule endpoints.\n\nCloses-Bug: #2150089\nRelated-Bug: #2149789\nRelated-Bug: #2149775\nAssisted-by: Claude Sonnet 4.6 \u003cnoreply@anthropic.com\u003e\nChange-Id: Iaaa0ec713a0a5e062acc3209d6010982899d8f6f\nSigned-off-by: Grzegorz Grasza \u003cxek@redhat.com\u003e\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n(cherry picked from commit 16582e5192be354e26ebef4badca1213ddc4dc07)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/fda177eb5a94ad6377fa912e44c90a3ccdb67f16"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/fda177eb5a94ad6377fa912e44c90a3ccdb67f16"}]},"branch":"refs/heads/stable/2025.2"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
