)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"e5d935a04440264eeb4c76aa2ecfe5ce6074cfa8","unresolved":true,"context_lines":[{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Assisted-by: claude"},{"line_number":21,"context_line":"Change-Id: I506950621a735079be7574b9ddde6ff6a0afdab7"},{"line_number":22,"context_line":"Signed-off-by: sarhiri \u003c143043927+sarhiri@users.noreply.github.com\u003e"},{"line_number":23,"context_line":"Signed-off-by: sarhiri \u003cm.sofiasarhiri@gmail.com\u003e"},{"line_number":24,"context_line":""},{"line_number":25,"context_line":"Reformat OSSN YAML files to OSSA-style format"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":4,"id":"940eca13_f7e0012e","line":22,"updated":"2026-08-07 20:32:36.000000000","message":"A few comments:\n- Please reduce to one group of commit message trailers\n- One signed-off-by per human, generally, and I don\u0027t think it\u0027s OK to have the hidden github email be the one signed off with here.\n- Please make sure this contains a full name as well. e.g.: Signed-off-by: Jay Faulkner \u003cjay@jvf.cc\u003e","commit_id":"356cfecb0cac05793d435d1aea9b1ca3695be938"}],"security-notes/OSSN-0004.yaml":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"0cab5f9c51b4becb79e8c43496ba64913e305fc5","unresolved":true,"context_lines":[{"line_number":15,"context_line":""},{"line_number":16,"context_line":"recommended-actions: \u003e"},{"line_number":17,"context_line":"  In the OpenStack Grizzly release, a user is allowed to update the attributes in their own entry by default. It is recommended that you restrict user updates to only be allowed by admin users. This is done by setting the \"update_user\" policy to \"admin_required\" in Keystone\u0027s policy.json file. Here is an example snippet of a properly configured policy.json file:"},{"line_number":18,"context_line":"  ---- begin example policy.json snippet ---- \"identity:get_user\": [[\"rule:admin_required\"]], \"identity:list_users\": [[\"rule:admin_required\"]], \"identity:create_user\": [[\"rule:admin_required\"]], \"identity:update_user\": [[\"rule:admin_required\"]], \"identity:delete_user\": [[\"rule:admin_required\"]], ---- end example policy.json snippet ----"},{"line_number":19,"context_line":"  This change has the side-effect of restricting a user from updating any of their own attributes, not just their password."},{"line_number":20,"context_line":"  In the OpenStack Havana release, the default policy is to only allow admin users to update attributes in user entries. In addition, Horizon will not allow a user to change their own password if it is using the Identity v3 API, even if Keystone is configured to allow users to update their own entries. Despite this restriction in Horizon, it is recommended to leave the default \"update_user\" policy setting as is, as an attacker could target Keystone directly without using Horizon to initiate a password change."},{"line_number":21,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"6fec1b13_e2625c90","line":18,"updated":"2026-08-07 20:31:07.000000000","message":"Please closely review these automated YAML migrations. Many of them -- especially the earlier ones -- are badly formatted like this.","commit_id":"356cfecb0cac05793d435d1aea9b1ca3695be938"}]}
