)]}'
{"id":"openstack%2Fneutron-lib~969481","triplet_id":"openstack%2Fneutron-lib~master~I45fd5d227fb6d6bf31e239e9d36f7b39f9b1257e","project":"openstack/neutron-lib","branch":"master","attention_set":{},"removed_from_attention_set":{"16688":{"account":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"last_update":"2025-12-04 17:52:28.000000000","reason":"\u003cGERRIT_ACCOUNT_16688\u003e replied on the change","reason_account":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"}},"11975":{"account":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"last_update":"2025-12-04 21:20:25.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"I45fd5d227fb6d6bf31e239e9d36f7b39f9b1257e","subject":"Add \"can_set_project_id\" attribute to the context object","status":"MERGED","created":"2025-12-03 15:25:10.000000000","updated":"2025-12-04 21:21:41.000000000","submitted":"2025-12-04 21:20:25.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":10,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"969481","meta_rev_id":"98bc42de79c9b54ea6cd3c5ca52d838a79b54942","_number":969481,"virtual_id_number":969481,"owner":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"value":0,"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2025-12-04 21:20:25.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"all":[{"value":2,"date":"2025-12-04 17:52:28.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"value":2,"date":"2025-12-04 19:07:30.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"all":[{"value":0,"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"value":1,"date":"2025-12-04 19:07:30.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"value":0,"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Gate Blocker Fix / Urgent Change"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2025-12-03 17:29:17.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2025-12-03 21:32:17.000000000","updated_by":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"reviewer":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"state":"CC"},{"updated":"2025-12-03 21:32:21.000000000","updated_by":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"reviewer":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"state":"REVIEWER"},{"updated":"2025-12-03 23:14:13.000000000","updated_by":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"reviewer":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"state":"CC"},{"updated":"2025-12-04 19:07:30.000000000","updated_by":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"reviewer":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"state":"REVIEWER"}],"messages":[{"id":"24b26e85464dbfad94b8aeb862ef38d09616df49","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2025-12-03 15:25:10.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"862ac5ac9120da98f863f7df8134cbc437725a88","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-03 17:29:17.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/545ca5605cfa44bab45635af3e9b637a\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d9d9565089534ced803053e1dd126a7d : SUCCESS in 7m 46s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/80c2ad50fb0043c692db8e0c6b63ba2d : SUCCESS in 2m 31s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/bfb20fd7adc04d1bae10309565785409 : SUCCESS in 2m 57s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/795ec2f9e4ee4916a16abb599aeeea44 : SUCCESS in 3m 33s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/7b2811033fc64ab5aa7e1b12fccbecfa : SUCCESS in 5m 11s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/43f3a1719100418488398bd6ef7d3092 : SUCCESS in 1h 43m 51s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ff2a367b69eb46baaf867105697e8322 : SUCCESS in 2m 31s\n- neutron-tempest-plugin-openvswitch https://zuul.opendev.org/t/openstack/build/a69a735d0dee4726957aa55eca221bda : SUCCESS in 1h 28m 53s\n- neutron-tempest-plugin-ovn https://zuul.opendev.org/t/openstack/build/f5d75f8696c34276b4d8773749810d63 : SUCCESS in 2h 02m 58s\n- neutron-tempest-plugin-designate-scenario https://zuul.opendev.org/t/openstack/build/ed8e1a9524f44af2827c25f32be104c5 : SUCCESS in 35m 09s\n- openstack-tox-py312-with-neutron https://zuul.opendev.org/t/openstack/build/440cbdb22ddb4f1a88383e742b4cd657 : SUCCESS in 24m 40s\n- openstack-tox-py312-with-sqlalchemy-master https://zuul.opendev.org/t/openstack/build/dba4de06d7454953b913d1503a8dd87e : SUCCESS in 5m 29s\n- neutron-functional https://zuul.opendev.org/t/openstack/build/9ecff28193bb44e183873c70e82e8902 : SUCCESS in 1h 38m 06s","accounts_in_message":[],"_revision_number":1},{"id":"129bd97b755131570cae5195f047fa24a8ab8d5c","author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"date":"2025-12-03 21:32:17.000000000","message":"Patch Set 1:\n\n(5 comments)","accounts_in_message":[],"_revision_number":1},{"id":"9599bb2af8fca73fe6d94d9822d02c3c9c72a401","author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"date":"2025-12-03 21:32:21.000000000","message":"Patch Set 1: Code-Review-1","accounts_in_message":[],"_revision_number":1},{"id":"746b01c840eb8ef5772fcb7aa0d942d3bfd43221","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2025-12-04 09:30:37.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1\n","accounts_in_message":[],"_revision_number":2},{"id":"1dad3fd5dd33abe99bcba559c67222bb2fc178b8","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2025-12-04 09:30:44.000000000","message":"Patch Set 1:\n\n(4 comments)","accounts_in_message":[],"_revision_number":1},{"id":"bf138c07f24cffb710b6721f7e486e5ed5894449","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-04 11:52:11.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/d0202d4e9e3b47ad8eb178457462ed09\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ab7fb533ff1449ba849841c59c799c8d : SUCCESS in 8m 27s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/ebb1cb3f3e5d40b5bee8ae9202161a0b : SUCCESS in 2m 26s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/b805123dd6e3446bb87b7287599dddb0 : SUCCESS in 5m 55s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/1813b7544349423781b9945412f91b7a : SUCCESS in 4m 15s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/4487981ba7ae4bc3ade671eace39b3c1 : SUCCESS in 6m 28s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/1bde737edfbe44c286a1594052188a7f : SUCCESS in 1h 43m 31s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/4a848a6dd509428c9f8da8a1cf0639c8 : SUCCESS in 3m 13s\n- neutron-tempest-plugin-openvswitch https://zuul.opendev.org/t/openstack/build/46a93060520f46f0a0a5ce974449bdca : SUCCESS in 1h 50m 16s\n- neutron-tempest-plugin-ovn https://zuul.opendev.org/t/openstack/build/2241fa85c91b4975b2a9f3162f2f9024 : SUCCESS in 2h 20m 37s\n- neutron-tempest-plugin-designate-scenario https://zuul.opendev.org/t/openstack/build/3a5722758a8e4470ace2ef55e6b9d42c : SUCCESS in 31m 09s\n- openstack-tox-py312-with-neutron https://zuul.opendev.org/t/openstack/build/4cf63d14e97d4eb8ae0319e2d99ca1ca : SUCCESS in 21m 17s\n- openstack-tox-py312-with-sqlalchemy-master https://zuul.opendev.org/t/openstack/build/8f2360436ee64a58941f3b2fe301d409 : SUCCESS in 5m 22s\n- neutron-functional https://zuul.opendev.org/t/openstack/build/68b339a6c5dd4fd48f90cd085c72ccd2 : SUCCESS in 1h 50m 02s","accounts_in_message":[],"_revision_number":2},{"id":"cd9a5af7825c7649f49458f2c4d3638ac4402c04","author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"date":"2025-12-04 17:52:28.000000000","message":"Patch Set 2: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"fefa3a63afccf15c783bd966f8cb900c0b7a1a28","author":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"date":"2025-12-04 19:07:30.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":2},{"id":"c2115c9f05f30527ea0696d6c28a3d0c2d3d5716","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-04 19:07:54.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"871a5135a601461fdc0937ebf0be0ebf96fdb9b2","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-04 21:20:25.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/51a4027696ea423898a20ba65d9c269f\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/653c8cd20ae248fe8d68d815aea28546 : SUCCESS in 8m 40s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/7b95000d74e2477c9aa42d91ad7466d8 : SUCCESS in 8m 13s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/e9a375b79fb14253b0ce776dd98bd52a : SUCCESS in 3m 18s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/2d27cd966b844306bf30ef1939cc5314 : SUCCESS in 8m 13s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/2987911a913b48118bb0341aa3f9d2e9 : SUCCESS in 1h 01m 16s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/1445e518549e44e88db775c3fef04de9 : SUCCESS in 4m 01s\n- neutron-tempest-plugin-openvswitch https://zuul.opendev.org/t/openstack/build/57b3bdf232304972b426e34d02e90ef5 : SUCCESS in 1h 31m 27s\n- neutron-tempest-plugin-ovn https://zuul.opendev.org/t/openstack/build/9cbbc862384248238fa0882bc31bbe3f : SUCCESS in 2h 09m 37s\n- neutron-functional https://zuul.opendev.org/t/openstack/build/6c653d92d9be4954948da816fcb82de4 : SUCCESS in 1h 52m 00s","accounts_in_message":[],"_revision_number":2},{"id":"2befa008731b482a13afef3b6ebb60a7913cf0c5","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-04 21:20:25.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"98bc42de79c9b54ea6cd3c5ca52d838a79b54942","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-12-04 21:21:41.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/227830e32dc747daaac4a765ae7c8dc6\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/5f3cdf87dc834e84bb48f078ffa7c3c6 : SUCCESS in 43s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/c00f3c3e6fdf4c5caf3a2d7a4bba990f : SUCCESS in 40s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"dde9ccfee032b8060d30631a1716fe6bcca728ad","revisions":{"8b705405367bbe4383ec6e085e8468d93969e813":{"kind":"REWORK","_number":1,"created":"2025-12-03 15:25:10.000000000","uploader":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"ref":"refs/changes/81/969481/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/neutron-lib","ref":"refs/changes/81/969481/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/1"}}},"commit":{"parents":[{"commit":"cdc293be4cf2ff118f71d6f4fda0019007f31f09","subject":"Merge \"Replace deprecated warn_on_missing_entrypoint\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron-lib/commit/cdc293be4cf2ff118f71d6f4fda0019007f31f09"}]}],"author":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2025-12-03 15:21:49.000000000","tz":60},"committer":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2025-12-03 15:25:06.000000000","tz":60},"subject":"Add \"can_set_project_id\" attribute to the context object","message":"Add \"can_set_project_id\" attribute to the context object\n\nIn case when API policies with custom roles has to be defined by the\noperator and such custom role should have granted persmission to\nsend project_id, other than own project_id in the request body, like for\nexample \"network_admin\" role who should be able to create networks on\nbehalv of every project in the cloud, it was not possible to achieve so far.\n\nThe problem was that for all non-admin and not service users, function\n``neutron_lib.api.attributes._validate_privileges`` had hardcoded that\nsending project_id in the request body is only allowed for admin and\nservice user (advsvc).\n\nThis patch introduces new API policy rule called\n`context_can_set_project_id` and attribute `can_set_project_id` to the\nneutron_lib.context.ContextBase class.\nBy default `context_can_set_project_id` rule is granted to nobody but it\ncan be defined in the neutron policy file like e.g.:\n\n    \"context_can_set_project_id\": \"role:network_admin\"\n\nThis doesn\u0027t mean that anyone with such role will be able to create\nanything for any project because there is still policy engine with\ndefined API policies which prevents that.\nSo to e.g. grant such network_admin user permission to create networks\nfor every project, additional rule would be needed in policy file and it\ncan looks like:\n\n\"create_network\": \"(rule:admin_only) or\n                   (role:member and project_id:%(project_id)s) or\n                   role:network_admin\"\n\nCloses-Bug: #2133212\n\nChange-Id: I45fd5d227fb6d6bf31e239e9d36f7b39f9b1257e\nSigned-off-by: Slawek Kaplonski \u003cskaplons@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron-lib/commit/8b705405367bbe4383ec6e085e8468d93969e813"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron-lib/commit/8b705405367bbe4383ec6e085e8468d93969e813"}]},"branch":"refs/heads/master"},"dde9ccfee032b8060d30631a1716fe6bcca728ad":{"kind":"REWORK","_number":2,"created":"2025-12-04 09:30:37.000000000","uploader":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"ref":"refs/changes/81/969481/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/neutron-lib","ref":"refs/changes/81/969481/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/neutron-lib refs/changes/81/969481/2"}}},"commit":{"parents":[{"commit":"cdc293be4cf2ff118f71d6f4fda0019007f31f09","subject":"Merge \"Replace deprecated warn_on_missing_entrypoint\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron-lib/commit/cdc293be4cf2ff118f71d6f4fda0019007f31f09"}]}],"author":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2025-12-03 15:21:49.000000000","tz":60},"committer":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2025-12-04 09:30:16.000000000","tz":60},"subject":"Add \"can_set_project_id\" attribute to the context object","message":"Add \"can_set_project_id\" attribute to the context object\n\nIn case when API policies with custom roles has to be defined by the\noperator and such custom role should have granted persmission to\nsend project_id, other than own project_id in the request body, like for\nexample \"network_admin\" role who should be able to create networks on\nbehalf of every project in the cloud, it was not possible to achieve so far.\n\nThe problem was that for all non-admin and not service users, function\n``neutron_lib.api.attributes._validate_privileges`` had hardcoded that\nsending project_id in the request body is only allowed for admin and\nservice user (advsvc).\n\nThis patch introduces new API policy rule called\n`context_can_set_project_id` and attribute `can_set_project_id` to the\nneutron_lib.context.ContextBase class.\nBy default `context_can_set_project_id` rule is granted to nobody but it\ncan be defined in the neutron policy file like e.g.:\n\n    \"context_can_set_project_id\": \"role:network_admin\"\n\nThis doesn\u0027t mean that anyone with such role will be able to create\nanything for any project because there is still policy engine with\ndefined API policies which prevents that.\nSo to e.g. grant such network_admin user permission to create networks\nfor every project, additional rule would be needed in policy file and it\ncan looks like:\n\n\"create_network\": \"(rule:admin_only) or\n                   (role:member and project_id:%(project_id)s) or\n                   role:network_admin\"\n\nCloses-Bug: #2133212\n\nChange-Id: I45fd5d227fb6d6bf31e239e9d36f7b39f9b1257e\nSigned-off-by: Slawek Kaplonski \u003cskaplons@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron-lib/commit/dde9ccfee032b8060d30631a1716fe6bcca728ad"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron-lib/commit/dde9ccfee032b8060d30631a1716fe6bcca728ad"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"}},{"label":"Review-Priority","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Review-Priority","description":"Review priority","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"-label:Review-Priority\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":[],"failing_atoms":["label:Review-Priority\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
