)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":4264,"name":"Matthias Runge","email":"mrunge@redhat.com","username":"mrunge"},"change_message_id":"55907bb32869d903982e55373661e338cc881f47","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"052adc8f_476c645e","updated":"2026-08-19 15:38:34.000000000","message":"This looks accurate to me","commit_id":"a4dbe776b23b4c78a221229ce1ed79fa7a98c1a2"},{"author":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"change_message_id":"321e219c782ef437c170c9601a24bb7d93b548e5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"f34c014e_75ecf91e","updated":"2026-08-19 15:59:38.000000000","message":"looks good","commit_id":"4ea3b722604c919b082f45629bb939c3938e749b"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"a2b6f87c9d7eddd73353901e2f02885a256e06f0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"2544c87b_ac91c27e","updated":"2026-08-19 16:01:23.000000000","message":"self-approving based on the chat on #openstack-security.","commit_id":"4ea3b722604c919b082f45629bb939c3938e749b"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"b9cafef39eedbab0056faba7968a5fccfac349d6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"b651fbe8_3daa85c4","updated":"2026-08-19 15:59:28.000000000","message":"that looks better thanks","commit_id":"4ea3b722604c919b082f45629bb939c3938e749b"}],"ossa/OSSA-2026-036.yaml":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"c21dc0db1835483983b8f6946d064d2500524a43","unresolved":false,"context_lines":[{"line_number":4,"context_line":""},{"line_number":5,"context_line":"title: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"description: \u003e"},{"line_number":8,"context_line":"  Chen YuXiang of the Institute of Computing Technology, Chinese"},{"line_number":9,"context_line":"  Academy of Sciences reported that OpenStack Aodh does not enforce"},{"line_number":10,"context_line":"  project scope on the alarm listing API when the ``all_projects``"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"1b0bb80c_a0d55140","line":7,"updated":"2026-08-19 15:12:52.000000000","message":"Nit: Keep in mind that since you\u0027re using a folding operator for this string, it\u0027s going to get flowed into a single paragraph, you may want `|` instead if you intended to keep it formatted as two distinct paragraphs.","commit_id":"ab36b3b38840fe23050807a69b0a5085e52e70c6"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"e956905de840ad62b64da506d2da4f8addb42e13","unresolved":true,"context_lines":[{"line_number":17,"context_line":"  The same reporter found that OpenStack Watcher does not apply"},{"line_number":18,"context_line":"  authorization to its webhook trigger endpoint. Any authenticated"},{"line_number":19,"context_line":"  user who learns an audit\u0027s webhook URL, for example from the Aodh"},{"line_number":20,"context_line":"  alarm metadata leaked above, can start an administrator-owned"},{"line_number":21,"context_line":"  ``EVENT`` audit and its associated action plan regardless of their"},{"line_number":22,"context_line":"  own project or role. All Watcher deployments are affected."},{"line_number":23,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":2,"id":"629b6bf4_01c3ed7a","line":20,"range":{"start_line":20,"start_character":44,"end_line":20,"end_character":63},"updated":"2026-08-19 15:49:53.000000000","message":"so i pointed this out in the bug and in the downstream draft\n\nwatcher resocus are not owned by a project usesr or role today\n\nthey are global system levle resocues like a nova host aggrate or a cinder volume type\n\nso its incorrect to call them administrator-owned\n\nwe should jsut say ` can start an ``Event`` based audit`\n\nthe desing of watcher has no concpet of audit ownership today and that is some thign we will have to evolve in the future but that is how watcehr was desgined from day 1\n\nthere was never any expection of owner ship so while we have add ed authrisation via a new policy that requries the admin role the audit and its assocated webhook is still not owned by a project or user and checkign either woudl be incorrect.\n\nuntil we change the watcher API and db to introduce the concept of tenants.","commit_id":"a4dbe776b23b4c78a221229ce1ed79fa7a98c1a2"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"a01253e1bd2e77aeb0f2eaa85bb819dc92c5492b","unresolved":true,"context_lines":[{"line_number":17,"context_line":"  The same reporter found that OpenStack Watcher does not apply"},{"line_number":18,"context_line":"  authorization to its webhook trigger endpoint. Any authenticated"},{"line_number":19,"context_line":"  user who learns an audit\u0027s webhook URL, for example from the Aodh"},{"line_number":20,"context_line":"  alarm metadata leaked above, can start an administrator-owned"},{"line_number":21,"context_line":"  ``EVENT`` audit and its associated action plan regardless of their"},{"line_number":22,"context_line":"  own project or role. All Watcher deployments are affected."},{"line_number":23,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":2,"id":"916c69d8_ec4efbe4","line":20,"range":{"start_line":20,"start_character":44,"end_line":20,"end_character":63},"in_reply_to":"629b6bf4_01c3ed7a","updated":"2026-08-19 15:51:00.000000000","message":"we can proceed without correcting this error but i would prefer to avoid propagating the idea that watcher resouce has owners today \n\nthe rest looks ok to me","commit_id":"a4dbe776b23b4c78a221229ce1ed79fa7a98c1a2"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"808f3093f08e27d2b142894adfffabeb19ad8e74","unresolved":true,"context_lines":[{"line_number":17,"context_line":"  The same reporter found that OpenStack Watcher does not apply"},{"line_number":18,"context_line":"  authorization to its webhook trigger endpoint. Any authenticated"},{"line_number":19,"context_line":"  user who learns an audit\u0027s webhook URL, for example from the Aodh"},{"line_number":20,"context_line":"  alarm metadata leaked above, can start an administrator-owned"},{"line_number":21,"context_line":"  ``EVENT`` audit and its associated action plan regardless of their"},{"line_number":22,"context_line":"  own project or role. All Watcher deployments are affected."},{"line_number":23,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":2,"id":"60134910_6e14f38f","line":20,"range":{"start_line":20,"start_character":44,"end_line":20,"end_character":63},"in_reply_to":"916c69d8_ec4efbe4","updated":"2026-08-19 15:52:33.000000000","message":"Ack; let me fix that up.","commit_id":"a4dbe776b23b4c78a221229ce1ed79fa7a98c1a2"},{"author":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"change_message_id":"321e219c782ef437c170c9601a24bb7d93b548e5","unresolved":true,"context_lines":[{"line_number":17,"context_line":"  The same reporter found that OpenStack Watcher does not apply"},{"line_number":18,"context_line":"  authorization to its webhook trigger endpoint. Any authenticated"},{"line_number":19,"context_line":"  user who learns an audit\u0027s webhook URL, for example from the Aodh"},{"line_number":20,"context_line":"  alarm metadata leaked above, can start an ``EVENT`` audit and its"},{"line_number":21,"context_line":"  associated action plan regardless of their own project or role."},{"line_number":22,"context_line":"  All Watcher deployments are affected."},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"affected-products:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"4c6c3063_4fe19f92","line":21,"range":{"start_line":20,"start_character":60,"end_line":21,"end_character":24},"updated":"2026-08-19 15:59:38.000000000","message":"yes, only for Audits originally created with auto_trigger\u003dtrue; but that\u0027s fine.","commit_id":"4ea3b722604c919b082f45629bb939c3938e749b"}]}
