)]}'
{"id":"openstack%2Fkeystone~993206","triplet_id":"openstack%2Fkeystone~master~I312332c646af2b02cf40459969d4228a3db1dd61","project":"openstack/keystone","branch":"master","attention_set":{"13478":{"account":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"last_update":"2026-06-24 16:26:25.000000000","reason":"Vote got outdated and was removed: Code-Review-1"}},"removed_from_attention_set":{"27900":{"account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"last_update":"2026-07-31 15:39:09.000000000","reason":"\u003cGERRIT_ACCOUNT_27900\u003e replied on the change","reason_account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}}},"hashtags":[],"change_id":"I312332c646af2b02cf40459969d4228a3db1dd61","subject":"Fix nullable enabled column security vulnerabilities for user and project","status":"NEW","created":"2026-06-13 09:48:23.000000000","updated":"2026-07-31 16:35:09.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":9,"unresolved_comment_count":7,"has_review_started":true,"meta_rev_id":"0bdf0239fc27ccfd949c446e6670767a5c96d72a","_number":993206,"virtual_id_number":993206,"owner":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"tag":"autogenerated:zuul:check","value":1,"date":"2026-07-31 16:35:09.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"recommended":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"value":1,"date":"2026-07-07 13:34:32.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-13 11:36:08.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-06-15 18:46:55.000000000","updated_by":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"reviewer":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"state":"REVIEWER"},{"updated":"2026-07-07 13:34:32.000000000","updated_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"}],"messages":[{"id":"c7b58a022d3b5ebdf423c4b74cd883827fdc2d29","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-06-13 09:48:23.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"5b2dc09e368e73fc40defda08d45ecdff8652a27","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-13 11:36:08.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/c8c6349b598a47389e22a5f0c272736c\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/714d6f873fb1414d803af3120eb940cc : SUCCESS in 10m 42s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/be7b2f7f2f8f401e86ff7a4afde4fe29 : SUCCESS in 3m 02s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/2f37da1e642041a2843e03c76950078d : SUCCESS in 7m 01s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/0992edf491094abb87c5288ff555eef1 : SUCCESS in 6m 58s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/662e9b5f756c479895704c076981f9d4 : SUCCESS in 8m 54s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d8cedd5c403240d3b3055ab954a660bd : SUCCESS in 11m 25s\n- grenade https://zuul.opendev.org/t/openstack/build/9eeacdc8ab2f40ca81ded6d96b00dc98 : SUCCESS in 31m 44s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/265c1267d6ad4162a1402fdfd64afb68 : SUCCESS in 1h 42m 25s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/9670bb0016c84c60999f5a105fd8b95e : SUCCESS in 6m 03s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/2617876124734aa68412e5be211d665d : SUCCESS in 16m 18s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/0b9571048c384c8a95fb734b04799d1f : SUCCESS in 13m 13s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/d8e325d718fc4f988b05dd7dd5951f34 : FAILURE in 17m 31s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/961317da2903433b9417220f2a5a3112 : FAILURE in 27m 24s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/1dcffc8c31af4996a8cf84715417c641 : SUCCESS in 18m 27s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/190a027be2794417bd574938a6d48f03 : SUCCESS in 41m 14s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/47edb38119fc457ebcaf776d2d941fa8 : SUCCESS in 37m 43s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/05236b4cadd84c1291cf1158070922f2 : SUCCESS in 40m 40s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/6b57dc0eca7c47caaff9922ebf99c53e : SUCCESS in 43m 42s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/64ab2e1823b445c4b940ee7fa2709034 : SUCCESS in 8m 15s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"3942cacadc5b303b1fd3de83e701d02182a6d09f","author":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"date":"2026-06-15 18:46:55.000000000","message":"Patch Set 1: Code-Review-1\n\n(7 comments)\n\nPatch Set 1: Code-Review-1\n\nNice, thanks.","accounts_in_message":[],"_revision_number":1},{"id":"19e217fb8d761a933c1bd75d1a946367f59830bc","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-17 01:16:58.000000000","message":"Patch Set 1:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/1f38c04570ae45d2bd68e0be256d2e9d\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/3aa5903be34743069ea3094d0bf3b610 : SUCCESS in 14m 15s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/d6a630a77f1a42568f8a9bff3be00988 : SUCCESS in 13m 18s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/d0342f64b65a471fb3ad06a4ed015be0 : SUCCESS in 33m 05s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"526ab2e2f36beadee3aab770fce47422eda20833","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-06-24 16:26:25.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"e2aa4baa2aacc7c11fe611e1e2c1cb191a9b4e3e","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-07-07 13:34:32.000000000","message":"Patch Set 2: Code-Review+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"8b7c53ea5f5dbd18389ca07115f6f68c8e391985","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-07 15:43:57.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/66014b6da08440629e248039e8d99a95\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/89da4f31b010459ab6ecb19578cf58df : SUCCESS in 18m 03s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5336395cbdd941e2b2ee168d8edcafb1 : SUCCESS in 5m 10s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/226a7fd6218241b1aac1d95ac3972d09 : SUCCESS in 11m 34s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/031550810ba4414faafb1bee847cb852 : SUCCESS in 10m 22s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/fc075a032b094c98b5a368ef0936b08f : SUCCESS in 17m 56s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/faf61d9c483945caa83b92c7fa3811c5 : SUCCESS in 7m 21s\n- grenade https://zuul.opendev.org/t/openstack/build/c51369c59de04c308dffd70ad6f49253 : SUCCESS in 1h 06m 17s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/a1e779c3f39c4d2bbfd45c1d3b5ffe66 : SUCCESS in 2h 03m 29s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/eb64f01001ee46b1aabbf086ecddef07 : SUCCESS in 13m 17s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/9d8287462d0b4155aeffa993636940bc : SUCCESS in 21m 52s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/a0f330d2ada9488e89eebb268a72486e : SUCCESS in 24m 56s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/c84e4007b24b487dad01efd5ec3674f0 : FAILURE in 20m 27s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/e074717aadb648558798964d786b4d54 : FAILURE in 13m 53s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/3a27fdc6476041f8b3310cac06cd1859 : SUCCESS in 55m 56s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/50a56dd22929445594664d979defa9b6 : FAILURE in 53m 22s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/f50df40006034a77941ba1829b0f46c9 : SUCCESS in 20m 53s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/d21fea61f28b47fcb4120c1fb1913014 : SUCCESS in 1h 03m 36s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/f175bc9127b84e0c90813e2900d68d67 : SUCCESS in 45m 01s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/bb8f66fffea74cc4acc62ae274a2fdca : SUCCESS in 8m 32s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":2},{"id":"89a72209fafacd8cb12015259ef01429c9d46acf","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-07 21:47:47.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/251aea51573247679b1487e17fcee922\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/1a8e369d97e84f569fe9e9db6a37b095 : SUCCESS in 15m 18s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/e1b4ae6b6af040a2ac3cfd01873dd7ef : SUCCESS in 39m 42s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/032d8c6070354918aa55341dc97711fd : TIMED_OUT in 1h 01m 26s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"f9981efdb84e61469208517699bc4ae6c65255a9","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-07-31 15:39:09.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"ce329e59c06f410a59be181f1dad09b35aba3326","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-31 16:15:56.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/0164097603f242c59ef2a204aeaa00a7\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/ca221f00a23b44298e5df5814f5a6693 : SUCCESS in 25m 18s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/eba9e3df69e84e74ac01fa26ae047827 : SUCCESS in 23m 17s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/c968801594cc423db76641db5cbbdbaa : SUCCESS in 34m 29s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"0bdf0239fc27ccfd949c446e6670767a5c96d72a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-31 16:35:09.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b0c974ddb77748828cfa2b78df905e5d\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c068fc6efdd24c21bbefaad80f5e68e1 : SUCCESS in 13m 14s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/4aa3ea2ea3554fd68b41047e0f925436 : SUCCESS in 3m 45s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/c0ad30fab1d14ac994fafe66c42cb000 : SUCCESS in 7m 58s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/6ab2b8b1366e491398c2af6eb8242e2c : SUCCESS in 6m 43s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/7d5fa61c25c84665a08f4c175f0a4baa : SUCCESS in 8m 43s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/fddf305e7a58416f8df61a2dc93c5d8f : SUCCESS in 13m 08s\n- grenade https://zuul.opendev.org/t/openstack/build/52ce8516ff2444408818ec7b97af9916 : SUCCESS in 36m 55s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/0d679e5b374b4eb9b7af6fad538c48f0 : SUCCESS in 42m 55s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/2f18ddbd16e34a118bc7542683f47e4a : SUCCESS in 13m 22s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/d5e0bee7c43b455eac073dee0c45fd9c : SUCCESS in 8m 06s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/06a3fea22a5c4f0497d0c5972ace830e : SUCCESS in 38m 49s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/e9c7a5bbe0634850958b9ec71bcc843a : FAILURE in 8m 29s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/820a561046004918a97db61b8124785f : FAILURE in 25m 34s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/14ef071d9bc344079e35c0680a70e819 : SUCCESS in 50m 35s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/67f9e6f20a40455883e9154e4df8dc4e : SUCCESS in 27m 20s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/7925fe263c4648efb00acba0bac6634e : SUCCESS in 37m 12s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/66c07b81aee843499d627e1d59bb4cf1 : SUCCESS in 33m 24s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/4eb036b240ef4d2999942b4013ca41ba : SUCCESS in 39m 31s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/e6eca1e89c4243b28f5b7cb7dc64e198 : SUCCESS in 4m 21s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"5a415940a8e18f44e5bf1952aa828839fbd4c740","revisions":{"d490848342bfaec538edb7d5baf7c26604f7a10e":{"kind":"REWORK","_number":1,"created":"2026-06-13 09:48:23.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/06/993206/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/06/993206/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/06/993206/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/06/993206/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/06/993206/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/06/993206/1"}}},"commit":{"parents":[{"commit":"eb3c0cd99a353fde717155aa80da4ddb4251ffe4","subject":"Merge \"Fix LDAP pagination to return all users beyond page_size\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/eb3c0cd99a353fde717155aa80da4ddb4251ffe4"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-06-03 08:49:13.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-06-13 09:47:46.000000000","tz":120},"subject":"Fix nullable enabled column security vulnerabilities for user and project","message":"Fix nullable enabled column security vulnerabilities for user and project\n\nThe `enabled` column on both `user` and `project` tables is nullable in\nthe database (no NULL constraint), allowing `enabled\u003dNULL` to exist.\nThis created inconsistent and potentially insecure behavior depending on\nwhich code path evaluated the enabled state. NULL values can appear in\nthe database through the regular create/update operations by\nspecifically passing `enabled: NULL`.\n\nUser vulnerabilities addressed:\n\n- PCI-DSS inactivity bypass: When `user._enabled` was `NULL`, the\n  hybrid property `enabled()` skipped the inactivity check due to the\n  condition `if self._enabled:` (None is falsy). This allowed dormant\n  user accounts to persist indefinitely without being auto-disabled,\n  violating PCI-DSS requirement 8.9. Fixed by changing to\n  `if self._enabled is not False:` so NULL-enabled users also undergo\n  inactivity checks.\n\nProject vulnerabilities addressed:\n\n-  Inconsistent enabled evaluation (Medium): Before this change,\n   project enabled checks used `.get(\u0027enabled\u0027, True)` which returned\n   `None` when the key existed with null value (default only applies\n   when key is absent). Python truthiness of `None` evaluated\n   differently depending on context:\n   - `not None` -\u003e True (blocked access - fail-closed)\n   - `any([None])` -\u003e False (incorrectly reported subtree as \"all\n     disabled\")\n   - `not self.project.get(\u0027enabled\u0027)` -\u003e True (blocked - fail-closed)\n     This inconsistency meant `enabled\u003dNone` could either block access\n     or allow unauthorized operations (parent project disable with\n     active children). Fixed by using explicit `.get(\u0027enabled\u0027, False)`\n     everywhere, making `enabled\u003dNone` consistently fail-closed\n     (treated as disabled).\n\nDefaults (backwards compatible):\n - User `enabled\u003dNone`: fail-open\n - Project `enabled\u003dNone`: fail-closed\n\nRelated-Bug: #2152715\nAssisted-By: qwen3.6\nChange-Id: I312332c646af2b02cf40459969d4228a3db1dd61\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d490848342bfaec538edb7d5baf7c26604f7a10e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d490848342bfaec538edb7d5baf7c26604f7a10e"}]},"branch":"refs/heads/master"},"5a415940a8e18f44e5bf1952aa828839fbd4c740":{"kind":"REWORK","_number":2,"created":"2026-06-24 16:26:25.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/06/993206/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/06/993206/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/06/993206/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/06/993206/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/06/993206/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/06/993206/2"}}},"commit":{"parents":[{"commit":"eb3c0cd99a353fde717155aa80da4ddb4251ffe4","subject":"Merge \"Fix LDAP pagination to return all users beyond page_size\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/eb3c0cd99a353fde717155aa80da4ddb4251ffe4"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-06-03 08:49:13.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-06-24 15:09:41.000000000","tz":120},"subject":"Fix nullable enabled column security vulnerabilities for user and project","message":"Fix nullable enabled column security vulnerabilities for user and project\n\nThe `enabled` column on both `user` and `project` tables is nullable in\nthe database (no NULL constraint), allowing `enabled\u003dNULL` to exist.\nThis created inconsistent and potentially insecure behavior depending on\nwhich code path evaluated the enabled state. NULL values can appear in\nthe database through the regular create/update operations by\nspecifically passing `enabled: NULL`.\n\nUser vulnerabilities addressed:\n\n- PCI-DSS inactivity bypass: When `user._enabled` was `NULL`, the\n  hybrid property `enabled()` skipped the inactivity check due to the\n  condition `if self._enabled:` (None is falsy). This allowed dormant\n  user accounts to persist indefinitely without being auto-disabled,\n  violating PCI-DSS requirement 8.9. Fixed by changing to\n  `if self._enabled is not False:` so NULL-enabled users also undergo\n  inactivity checks.\n\nProject vulnerabilities addressed:\n\n-  Inconsistent enabled evaluation (Medium): Before this change,\n   project enabled checks used `.get(\u0027enabled\u0027, True)` which returned\n   `None` when the key existed with null value (default only applies\n   when key is absent). Python truthiness of `None` evaluated\n   differently depending on context:\n   - `not None` -\u003e True (blocked access - fail-closed)\n   - `any([None])` -\u003e False (incorrectly reported subtree as \"all\n     disabled\")\n   - `not self.project.get(\u0027enabled\u0027)` -\u003e True (blocked - fail-closed)\n     This inconsistency meant `enabled\u003dNone` could either block access\n     or allow unauthorized operations (parent project disable with\n     active children). Fixed by using explicit `.get(\u0027enabled\u0027, False)`\n     everywhere, making `enabled\u003dNone` consistently fail-closed\n     (treated as disabled).\n\nDefaults (backwards compatible):\n - User `enabled\u003dNone`: fail-open\n - Project `enabled\u003dNone`: fail-closed\n\nRelated-Bug: #2152715\nAssisted-By: qwen3.6\nChange-Id: I312332c646af2b02cf40459969d4228a3db1dd61\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5a415940a8e18f44e5bf1952aa828839fbd4c740"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5a415940a8e18f44e5bf1952aa828839fbd4c740"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"}},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
