)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":9303,"name":"Abhishek Kekane","email":"akekane@redhat.com","username":"abhishekkekane"},"change_message_id":"f92c77fdd1047b5d30c0cbd094e5a7d5bc70ba25","unresolved":true,"context_lines":[{"line_number":10,"context_line":"and backported as it is in Wallaby including the glance policies for"},{"line_number":11,"context_line":"those apis as well which doesn\u0027t have project-persona support implemented"},{"line_number":12,"context_line":"in Wallaby. In glance, SRBAC project-persona support for few apis was"},{"line_number":13,"context_line":"added/updated in Xena cycle, ex. metadef apis \u0026 modify_image."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Modifying the glance default policies for metadef apis \u0026 modify image in"},{"line_number":16,"context_line":"enable-secure-rbac.yaml according to the core glance policies there"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"305f4ef9_3c188c68","line":13,"range":{"start_line":13,"start_character":48,"end_line":13,"end_character":60},"updated":"2022-07-26 10:11:09.000000000","message":"this should be modify_member","commit_id":"8ffc1367a01047531aae7b2204cac0e494b1f194"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"aaa9a2ddf08f94bdcc1560128a02a4c56f4336ca","unresolved":false,"context_lines":[{"line_number":10,"context_line":"and backported as it is in Wallaby including the glance policies for"},{"line_number":11,"context_line":"those apis as well which doesn\u0027t have project-persona support implemented"},{"line_number":12,"context_line":"in Wallaby. In glance, SRBAC project-persona support for few apis was"},{"line_number":13,"context_line":"added/updated in Xena cycle, ex. metadef apis \u0026 modify_image."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Modifying the glance default policies for metadef apis \u0026 modify image in"},{"line_number":16,"context_line":"enable-secure-rbac.yaml according to the core glance policies there"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"c33d8cdb_017c6fcc","line":13,"range":{"start_line":13,"start_character":48,"end_line":13,"end_character":60},"in_reply_to":"305f4ef9_3c188c68","updated":"2022-07-26 10:13:31.000000000","message":"Done","commit_id":"8ffc1367a01047531aae7b2204cac0e494b1f194"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"5a5158624161658c0362b94f2ab433f09d19e2db","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     Pranali Deore \u003cpdeore@redhat.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-07-26 10:12:41 +0000"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"[Wallaby-Only]Modify glance default THT policies as per core glance policies"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change[1] had added some default policies for all the services,"},{"line_number":10,"context_line":"and backported as it is in Wallaby including the glance policies for"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"36196aff_52dd6688","line":7,"updated":"2022-07-27 18:44:25.000000000","message":"nit: as a commit subject, this line is too long\n\nMore important, though, is I don\u0027t think you want to use the word \"default\", because they\u0027re actually policy overrides that implement secure-rbac. Nor are these THT policies.\n\nIf I understand the intent correctly, what this patch is doing is it fixes glance\u0027s secure-rbac policies to match glance\u0027s implementation in wallaby.\n\nIf my understanding is correct, something like the following line would make more sense (at least to me):\n\n[Wallaby-Only] Fix glance secure-rbac policies","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"eef476343188d044fe1ea379e5c82200a5c7265a","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     Pranali Deore \u003cpdeore@redhat.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2022-07-26 10:12:41 +0000"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"[Wallaby-Only]Modify glance default THT policies as per core glance policies"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change[1] had added some default policies for all the services,"},{"line_number":10,"context_line":"and backported as it is in Wallaby including the glance policies for"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"9217855b_d9a43db6","line":7,"in_reply_to":"36196aff_52dd6688","updated":"2022-07-29 11:16:14.000000000","message":"Yeah right, it looks quite lengthy.","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"5a5158624161658c0362b94f2ab433f09d19e2db","unresolved":true,"context_lines":[{"line_number":7,"context_line":"[Wallaby-Only]Modify glance default THT policies as per core glance policies"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change[1] had added some default policies for all the services,"},{"line_number":10,"context_line":"and backported as it is in Wallaby including the glance policies for"},{"line_number":11,"context_line":"those apis as well which doesn\u0027t have project-persona support implemented"},{"line_number":12,"context_line":"in Wallaby. In glance, SRBAC project-persona support for few apis was"},{"line_number":13,"context_line":"added/updated in Xena cycle, ex. metadef apis \u0026 modify_member."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Modifying the glance default policies for metadef apis \u0026 modify image in"},{"line_number":16,"context_line":"enable-secure-rbac.yaml according to the core glance policies there"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"9441a03f_2c842d69","line":13,"range":{"start_line":10,"start_character":35,"end_line":13,"end_character":62},"updated":"2022-07-27 18:44:25.000000000","message":"I had to read this a few times before I understood what\u0027s happening. Glance modified some policies (the list of them doesn\u0027t matter) in xena, and so the policy overrides for secure-rbac that were backported to wallaby won\u0027t work with glance\u0027s wallaby code. \n\nThis patch fixes the secure-rbac policy overrides so that they work with wallaby code.\n\nIs that correct?","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"eef476343188d044fe1ea379e5c82200a5c7265a","unresolved":true,"context_lines":[{"line_number":7,"context_line":"[Wallaby-Only]Modify glance default THT policies as per core glance policies"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This change[1] had added some default policies for all the services,"},{"line_number":10,"context_line":"and backported as it is in Wallaby including the glance policies for"},{"line_number":11,"context_line":"those apis as well which doesn\u0027t have project-persona support implemented"},{"line_number":12,"context_line":"in Wallaby. In glance, SRBAC project-persona support for few apis was"},{"line_number":13,"context_line":"added/updated in Xena cycle, ex. metadef apis \u0026 modify_member."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Modifying the glance default policies for metadef apis \u0026 modify image in"},{"line_number":16,"context_line":"enable-secure-rbac.yaml according to the core glance policies there"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"5d4ee3ef_19e29666","line":13,"range":{"start_line":10,"start_character":35,"end_line":13,"end_character":62},"in_reply_to":"9441a03f_2c842d69","updated":"2022-07-29 11:16:14.000000000","message":"Correct, I will modify it.","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"},{"author":{"_account_id":21129,"name":"Alan Bishop","email":"abishopsweng@gmail.com","username":"ASBishop","status":"ex Red Hat"},"change_message_id":"5a5158624161658c0362b94f2ab433f09d19e2db","unresolved":true,"context_lines":[{"line_number":16,"context_line":"enable-secure-rbac.yaml according to the core glance policies there"},{"line_number":17,"context_line":"in wallaby."},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"[1]: https://review.opendev.org/q/I9957243d307758f56b84cde3a408006d8161fa41"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"Change-Id: I899edff51233e61609071b340ab9eb05ed6e398a"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"593aecfb_e4ef280e","line":19,"updated":"2022-07-27 18:44:25.000000000","message":"tip: gerrit is smart enough to recognize change IDs and display them as hyperlinks, so you can remove all the \"https://review...\" stuff and just list the change-id, like this:\n\n[1] I9957243d307758f56b84cde3a408006d8161fa41","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"eef476343188d044fe1ea379e5c82200a5c7265a","unresolved":false,"context_lines":[{"line_number":16,"context_line":"enable-secure-rbac.yaml according to the core glance policies there"},{"line_number":17,"context_line":"in wallaby."},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"[1]: https://review.opendev.org/q/I9957243d307758f56b84cde3a408006d8161fa41"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"Change-Id: I899edff51233e61609071b340ab9eb05ed6e398a"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":3,"id":"21f2fd0f_fa852de6","line":19,"in_reply_to":"593aecfb_e4ef280e","updated":"2022-07-29 11:16:14.000000000","message":"Done","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":9303,"name":"Abhishek Kekane","email":"akekane@redhat.com","username":"abhishekkekane"},"change_message_id":"f92c77fdd1047b5d30c0cbd094e5a7d5bc70ba25","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"cafc61e5_cc2b4051","updated":"2022-07-26 10:11:09.000000000","message":"Looks good need to change commit message.","commit_id":"8ffc1367a01047531aae7b2204cac0e494b1f194"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"aaa9a2ddf08f94bdcc1560128a02a4c56f4336ca","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"718cca3d_e79d14f9","in_reply_to":"cafc61e5_cc2b4051","updated":"2022-07-26 10:13:31.000000000","message":"Thanks !! :)","commit_id":"8ffc1367a01047531aae7b2204cac0e494b1f194"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"eef476343188d044fe1ea379e5c82200a5c7265a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"fbbaa867_ee7328ac","updated":"2022-07-29 11:16:14.000000000","message":"Thanks Alan, I will fix comments on the commit message. ","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"428b674415ba90876c7d217fee1e37f3f197bca6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"691aa53c_23516ca7","updated":"2022-07-26 15:28:10.000000000","message":"recheck","commit_id":"9d9f1c17ab183ae842d3e367fe8e65e38e0de68c"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"012d3b81c5302de192a54287ba5fd2f42dd925bf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"06e30d6d_ce5dbcb5","updated":"2022-08-01 14:26:20.000000000","message":"recheck","commit_id":"4b12b608af218105f5f9e21a055ba04b893e6bdf"},{"author":{"_account_id":8449,"name":"Marios Andreou","email":"marios.andreou@gmail.com","username":"marios"},"change_message_id":"54d5b4ed8aa5a8018b84eb3ae78296f6fc0006b2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"6caa2d7a_8972931d","updated":"2022-08-01 07:38:13.000000000","message":"this is really hard to review without being familiar with the rbac policies for glance (and the wallaby ones, specifically at that).\n\nis there something you can point to for reviewers to check?\n\neg i cant see if you have missed any or if the ones you have altered are correct.","commit_id":"4b12b608af218105f5f9e21a055ba04b893e6bdf"},{"author":{"_account_id":8449,"name":"Marios Andreou","email":"marios.andreou@gmail.com","username":"marios"},"change_message_id":"c4e6520255b395fbb027363398796ced10cab810","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"7a809202_0d6b9119","in_reply_to":"6caa2d7a_8972931d","updated":"2022-08-01 07:38:30.000000000","message":"any tests you can point to for example?","commit_id":"4b12b608af218105f5f9e21a055ba04b893e6bdf"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"fd8a75fae253061ee3ecc7935fc9a4fb09d8e95c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"1a707e18_bf5d934a","in_reply_to":"7a809202_0d6b9119","updated":"2022-08-01 14:32:49.000000000","message":"Hey Marios,\n\nFor glance wallaby polices, you can refer policies from glance codebase and glance-tempest-plugin tests,\n[1]: https://github.com/openstack/glance/blob/stable/wallaby/glance/policies/image.py\n[2]: https://github.com/openstack/glance/blob/stable/wallaby/glance/policies/metadef.py\n[3]: https://opendev.org/openstack/glance-tempest-plugin/src/tag/0.2.0/glance_tempest_plugin/tests/rbac/v2/test_images.py","commit_id":"4b12b608af218105f5f9e21a055ba04b893e6bdf"}],"environments/enable-secure-rbac.yaml":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"fc7368e19c07ca4155fe75eae0daba840156cb0a","unresolved":true,"context_lines":[{"line_number":1535,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""},{"line_number":1536,"context_line":"    glance-get_member:"},{"line_number":1537,"context_line":"      key: \"get_member\""},{"line_number":1538,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1539,"context_line":"    glance-get_members:"},{"line_number":1540,"context_line":"      key: \"get_members\""},{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"07963ef2_5548a285","line":1538,"range":{"start_line":1538,"start_character":71,"end_line":1538,"end_character":98},"updated":"2022-08-01 02:05:41.000000000","message":"I think we should remove this also.\n\nhttps://review.opendev.org/c/openstack/glance/+/802996/10/glance/policies/image.py","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"a7bffd1e19119fa59f33841041cea7c8d8f507e1","unresolved":false,"context_lines":[{"line_number":1535,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""},{"line_number":1536,"context_line":"    glance-get_member:"},{"line_number":1537,"context_line":"      key: \"get_member\""},{"line_number":1538,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1539,"context_line":"    glance-get_members:"},{"line_number":1540,"context_line":"      key: \"get_members\""},{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"993835fa_fa0d1218","line":1538,"range":{"start_line":1538,"start_character":71,"end_line":1538,"end_character":98},"in_reply_to":"07963ef2_5548a285","updated":"2022-08-01 06:27:12.000000000","message":"Done","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"fc7368e19c07ca4155fe75eae0daba840156cb0a","unresolved":true,"context_lines":[{"line_number":1538,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1539,"context_line":"    glance-get_members:"},{"line_number":1540,"context_line":"      key: \"get_members\""},{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1542,"context_line":"    glance-modify_member:"},{"line_number":1543,"context_line":"      key: \"modify_member\""},{"line_number":1544,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"fb1cac18_5b90fbf7","line":1541,"range":{"start_line":1541,"start_character":70,"end_line":1541,"end_character":99},"updated":"2022-08-01 02:05:41.000000000","message":"ditto","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"},{"author":{"_account_id":19138,"name":"Pranali Deore","email":"pdeore@redhat.com","username":"PranaliD"},"change_message_id":"a7bffd1e19119fa59f33841041cea7c8d8f507e1","unresolved":false,"context_lines":[{"line_number":1538,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1539,"context_line":"    glance-get_members:"},{"line_number":1540,"context_line":"      key: \"get_members\""},{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1542,"context_line":"    glance-modify_member:"},{"line_number":1543,"context_line":"      key: \"modify_member\""},{"line_number":1544,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"ea39b3da_e374b9c4","line":1541,"range":{"start_line":1541,"start_character":70,"end_line":1541,"end_character":99},"in_reply_to":"fb1cac18_5b90fbf7","updated":"2022-08-01 06:27:12.000000000","message":"Done","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"fc7368e19c07ca4155fe75eae0daba840156cb0a","unresolved":true,"context_lines":[{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1542,"context_line":"    glance-modify_member:"},{"line_number":1543,"context_line":"      key: \"modify_member\""},{"line_number":1544,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""},{"line_number":1545,"context_line":"    glance-manage_image_cache:"},{"line_number":1546,"context_line":"      key: \"manage_image_cache\""},{"line_number":1547,"context_line":"      value: \"role:admin\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"8ac62599_3279de68","line":1544,"range":{"start_line":1544,"start_character":45,"end_line":1544,"end_character":70},"updated":"2022-08-01 02:05:41.000000000","message":"We should also fix this in maser, right ?\nThis should be (project_id:%(project_id)s or project_id:%(member_id)s) in master IIUC.","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"},{"author":{"_account_id":9303,"name":"Abhishek Kekane","email":"akekane@redhat.com","username":"abhishekkekane"},"change_message_id":"7bef09c3a5cfa6129898167f7b5294895cbff725","unresolved":true,"context_lines":[{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1542,"context_line":"    glance-modify_member:"},{"line_number":1543,"context_line":"      key: \"modify_member\""},{"line_number":1544,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""},{"line_number":1545,"context_line":"    glance-manage_image_cache:"},{"line_number":1546,"context_line":"      key: \"manage_image_cache\""},{"line_number":1547,"context_line":"      value: \"role:admin\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"cfa6d966_1017d6e5","line":1544,"range":{"start_line":1544,"start_character":45,"end_line":1544,"end_character":70},"in_reply_to":"8ac62599_3279de68","updated":"2022-08-01 05:01:22.000000000","message":"Policy is right in master branch, we do changed it during xena cycle.","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"8f96ffbcb36f68a5e2690fb658a31680c45f128f","unresolved":false,"context_lines":[{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1542,"context_line":"    glance-modify_member:"},{"line_number":1543,"context_line":"      key: \"modify_member\""},{"line_number":1544,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""},{"line_number":1545,"context_line":"    glance-manage_image_cache:"},{"line_number":1546,"context_line":"      key: \"manage_image_cache\""},{"line_number":1547,"context_line":"      value: \"role:admin\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"57951504_113a92a6","line":1544,"range":{"start_line":1544,"start_character":45,"end_line":1544,"end_character":70},"in_reply_to":"8d02f5f6_69246192","updated":"2022-08-01 05:11:36.000000000","message":"Nevermind. I noticed I misread the policy and modify_member uses the different check_str which is ADMIN_OR_SHARED_MEMBER .","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"e0652fba41541018f7b6ab2e9a11835a4fcd356c","unresolved":false,"context_lines":[{"line_number":1541,"context_line":"      value: \"role:admin or role:reader and (project_id:%(project_id)s or project_id:%(member_id)s)\""},{"line_number":1542,"context_line":"    glance-modify_member:"},{"line_number":1543,"context_line":"      key: \"modify_member\""},{"line_number":1544,"context_line":"      value: \"role:admin or (role:member and project_id:%(project_id)s)\""},{"line_number":1545,"context_line":"    glance-manage_image_cache:"},{"line_number":1546,"context_line":"      key: \"manage_image_cache\""},{"line_number":1547,"context_line":"      value: \"role:admin\""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"8d02f5f6_69246192","line":1544,"range":{"start_line":1544,"start_character":45,"end_line":1544,"end_character":70},"in_reply_to":"cfa6d966_1017d6e5","updated":"2022-08-01 05:09:44.000000000","message":"The default policy in glance master allows this not only shared members but also the project owning the image to use this API.\nhttps://github.com/openstack/glance/blob/1ef06ef08ba177bd9ea93c25f96fa13aa6a2e9de/glance/policies/image.py#L249\n\nHowever the latest policy rule we use in tripleo master does not allow the owner project to use this API. Is this difference intentional ?\nhttps://github.com/openstack/tripleo-heat-templates/blob/210a2dac77b260fa0d9fb06f3b0b8ba82a3ab145/environments/enable-secure-rbac.yaml#L1544\n\nAnyway I\u0027ll propose a change to \"fix\" it and we can discuss it further in a separate patch.","commit_id":"5b0af35af2bb2013c616537983f8abc0829cb77f"}]}
