)]}'
{"id":"openstack%2Fwatcher~1001505","triplet_id":"openstack%2Fwatcher~master~Ic56f82c6825f0dc8e83ee92a92e3c3479404252d","project":"openstack/watcher","branch":"master","topic":"bug/2161771","attention_set":{},"removed_from_attention_set":{"30002":{"account":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"last_update":"2026-08-19 19:23:10.000000000","reason":"Change was submitted"},"11604":{"account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"last_update":"2026-08-19 15:31:53.000000000","reason":"\u003cGERRIT_ACCOUNT_11604\u003e replied on the change","reason_account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},"26471":{"account":{"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},"last_update":"2026-08-19 15:39:26.000000000","reason":"removed on reply"}},"hashtags":["CVE-2026-76878","OSSA-2026-036"],"change_id":"Ic56f82c6825f0dc8e83ee92a92e3c3479404252d","subject":"Add policy enforcement to webhook trigger endpoint","status":"MERGED","created":"2026-08-19 14:11:57.000000000","updated":"2026-08-20 06:15:04.000000000","submitted":"2026-08-19 19:23:10.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":3,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1001505-bug/2161771","meta_rev_id":"a4e0d80072a8eacadb5947eac53c74dc17e35139","_number":1001505,"virtual_id_number":1001505,"owner":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-08-19 19:23:10.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":2,"date":"2026-08-19 15:31:53.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":-1,"date":"2026-08-19 15:39:26.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":1,"date":"2026-08-19 15:31:53.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{" 0":"Standard Change","+1":"Important Change","+2":"High Priority Change"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"}],"CC":[{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-19 14:12:06.000000000","updated_by":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"reviewer":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"state":"CC"},{"updated":"2026-08-19 14:16:18.000000000","updated_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"reviewer":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"state":"REVIEWER"},{"updated":"2026-08-19 14:43:13.000000000","updated_by":{"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},"reviewer":{"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},"state":"REVIEWER"},{"updated":"2026-08-19 17:31:38.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"bb93ac768ab9ec7fccb4de9a1bffcc433a8bfc84","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"date":"2026-08-19 14:11:57.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"128531cbc405c1272b2ba94a2d0bf5048d4a1fef","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-08-19 14:12:06.000000000","message":"Patch Set 1:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":1},{"id":"efff8673d11035458f6b7d9bd729aa6f574529fc","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-08-19 14:16:18.000000000","message":"Patch Set 1: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":1},{"id":"dc24c6a4d390165d2940ccb1c9e03f9be79ae470","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-08-19 14:26:27.000000000","message":"Patch Set 1:\n\n(1 comment)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/eea72b35ec27451eb84257287ebc620b\n\n- teim-code-review https://zuul.teim.app/t/main/build/9fb383da87754d1ba22e7220019addc7 : SUCCESS in 14m 13s","accounts_in_message":[],"_revision_number":1},{"id":"706be342a678c2918b07eabbfc2789916d31fffc","author":{"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},"date":"2026-08-19 14:43:13.000000000","message":"Patch Set 1: Code-Review-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\nhttps://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/4a5670006a034f7dbb9b4cb6d54b3c36\n\n- openstack-meta-content-provider-master https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/build/37f2ef43f9c94cb38bd02a900366f3cb : FAILURE in 11m 24s\n- watcher-operator-validation-master https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/build/1b749dd9f50345419ebb047d7d679d5e : SKIPPED Skipped due to failed job openstack-meta-content-provider-master","accounts_in_message":[],"_revision_number":1},{"id":"a8caf1ec664a69b54503d7f5b79ed49b7d3c1a05","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"date":"2026-08-19 15:01:51.000000000","message":"Hashtag added: OSSA-2026-036","accounts_in_message":[],"_revision_number":1},{"id":"ae825535db56718fc383ca199e36614eaffab4f9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"date":"2026-08-19 15:24:00.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review+2, Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Workflow+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"13ed18ffcb78b8c958aff0cb60c93e698a7e0388","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-08-19 15:24:07.000000000","message":"Patch Set 2:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":2},{"id":"5d626cdb33cf87e5e0690f3c95d4ebc1d042c819","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-08-19 15:31:53.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"4c7e534a519bb9390ef2222e818414449e529dc5","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-08-19 15:33:12.000000000","message":"Patch Set 2:\n\n(1 comment)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/6dc00dca42db4e8890a0c7c8a5cf0dd2\n\n- teim-code-review https://zuul.teim.app/t/main/build/8e949a6263c542bdab71eb3605d93083 : SUCCESS in 8m 55s\n\nWarning:\n  The commit message body reads \"This patch introduce a new webhook policy module with a webhook:trigger rule\", where the subject-verb disagreement (\u0027introduce\u0027 instead of \u0027introduces\u0027) is a clear grammar error in the permanent change history. The intended meaning remains obvious, so this is a low-impact wording defect rather than an ambiguity.\n\n**Severity**: SUGGESTION | **Confidence**: 0.92\n\n**Impact**: Minor: permanent history readability for a security-relevant change; no effect on code behavior or merge safety.\n\n**Recommendation**:\nAmend the commit message to \"This patch introduces a new webhook policy module...\" before merging.","accounts_in_message":[],"_revision_number":2},{"id":"40e2ce520e8a24c08b8d26d55bea73ba1fc1e513","author":{"_account_id":26471,"name":"Software Factory CI","email":"softwarefactory-operations-team@redhat.com","username":"sf-project-io"},"date":"2026-08-19 15:39:26.000000000","message":"Patch Set 2: Code-Review-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\nhttps://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/e3eb36ca65964b96876d5075f1c508fd\n\n- openstack-meta-content-provider-master https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/build/b1a2337da36c4ce1950a735e4d7affc6 : FAILURE in 9m 45s\n- watcher-operator-validation-master https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/build/a424142f61754ef99dd7d7cec60ef610 : SKIPPED Skipped due to failed job openstack-meta-content-provider-master","accounts_in_message":[],"_revision_number":2},{"id":"55f87f43c57d7444566c0c46414d218e48db9166","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-19 17:31:38.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/1b6475a7f215445ebd2b068089299ac2\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c16d3ea88cf4410585efe531ec76871a : SUCCESS in 4m 11s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/83792b402dce4db8a73b56b8320ad2dc : SUCCESS in 4m 19s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/ae687b1e15cb40059814da44b33865e8 : SUCCESS in 3m 17s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/ec20df2bde4647d1b0b2f9322c5c5d44 : SUCCESS in 5m 21s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/cdf6889e0fe247a7b2c14074d4e05365 : SUCCESS in 8m 22s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4272d46c7d3c462c9e421871abf60235 : SUCCESS in 4m 43s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/613f41f2708f4b478c8c0180dac162ad : SUCCESS in 4m 29s\n- openstack-tox-py313-eventlet https://zuul.opendev.org/t/openstack/build/186750cb6f9a4c4ea5ac8265fd572f8e : SUCCESS in 5m 02s\n- watcher-grenade https://zuul.opendev.org/t/openstack/build/ea72388b506a4fb4a63bec7baa45a88a : SUCCESS in 24m 03s\n- watcher-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/63180b007705426bb6a52d45cd95c5b0 : SUCCESS in 52m 02s\n- watcher-tempest-api-ipv6-only https://zuul.opendev.org/t/openstack/build/bca67998ce0140deb8887d14b3856432 : SUCCESS in 39m 58s\n- watcher-tempest-gnocchi https://zuul.opendev.org/t/openstack/build/92a3d58128e34173b05bd0cd640c06c7 : SUCCESS in 1h 34m 46s\n- python-watcherclient-functional https://zuul.opendev.org/t/openstack/build/c27d9f56b4ae4254a67cf42354df5ca3 : SUCCESS in 14m 58s\n- watcher-tempest-prometheus https://zuul.opendev.org/t/openstack/build/00ca0be52aa44f4b99efdad360818b07 : SUCCESS in 1h 34m 03s\n- watcher-tempest-prometheus-eventlet https://zuul.opendev.org/t/openstack/build/71c6aefcc4aa4b4f9a3569a2f9b75d23 : SUCCESS in 1h 31m 46s\n- watcher-tempest-aetos https://zuul.opendev.org/t/openstack/build/123fbcee73af4f5fa686bfa75a190577 : SUCCESS in 47m 08s\n- openstack-tox-functional-py313 https://zuul.opendev.org/t/openstack/build/0051722f9eae4e38adb013ad773652f9 : SUCCESS in 4m 21s","accounts_in_message":[],"_revision_number":2},{"id":"f99c1b5d2dd012e6f1247369ef43c98f3d7b457c","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-19 17:32:59.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"4a590ecd887c0714f3bfd1d81ecb530aceec3b0b","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-19 19:23:10.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ea80dd66bd9f4e6d90e653f69a45692d\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a820cac61a48485dab665580a61042ee : SUCCESS in 2m 38s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/b1da210d1ec048f9b5ed66578a4d11b3 : SUCCESS in 5m 15s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/16fb046191d8465e9b840643b36ea47d : SUCCESS in 5m 31s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/791d4448379e474abc975a210460003f : SUCCESS in 9m 42s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/1583ff6f56114afc96e857a84af3e951 : SUCCESS in 2m 40s\n- openstack-tox-py313-eventlet https://zuul.opendev.org/t/openstack/build/b3eaf38b4eaf41e39f8279c43d5dddd5 : SUCCESS in 6m 06s\n- watcher-grenade https://zuul.opendev.org/t/openstack/build/8f0f1d2e0b75456bbb2dc1f58e89d184 : SUCCESS in 51m 10s\n- watcher-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/6b45a5cac4594f7f872fb14611471bab : SUCCESS in 38m 08s\n- watcher-tempest-api-ipv6-only https://zuul.opendev.org/t/openstack/build/4bcdb8fae7f4421a97149bb31b7268e5 : SUCCESS in 34m 46s\n- watcher-tempest-gnocchi https://zuul.opendev.org/t/openstack/build/60862dc7f2e04887b915b222fac3ba0b : SUCCESS in 1h 26m 49s\n- python-watcherclient-functional https://zuul.opendev.org/t/openstack/build/d1bb63e3a7b64349be05cdf24819a69b : SUCCESS in 22m 30s\n- watcher-tempest-prometheus https://zuul.opendev.org/t/openstack/build/31979b42aca14f13b85630f1d731ce99 : SUCCESS in 1h 43m 27s\n- watcher-tempest-prometheus-eventlet https://zuul.opendev.org/t/openstack/build/088262de26064560bca72291c2e7d819 : SUCCESS in 52m 05s\n- watcher-tempest-aetos https://zuul.opendev.org/t/openstack/build/159e38eef7834063a1e6a2940dcc1661 : SUCCESS in 1h 40m 07s\n- openstack-tox-functional-py313 https://zuul.opendev.org/t/openstack/build/e174ef9bde9b435e89fedb9e7f035938 : SUCCESS in 3m 40s","accounts_in_message":[],"_revision_number":2},{"id":"80eee479f1ba45d31f8263a4a789c037cf9f6cd3","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-19 19:23:10.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"a45ef7449636f750b7cba9d6636500daef93f49b","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-19 19:24:07.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/5350c8d87628477b954e3cb66e551f42\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/84b95f46daf848ca9bdf5c911d91be5d : SUCCESS in 42s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d762856f86aa464086c1b0e6fdf425c1 : SUCCESS in 40s","accounts_in_message":[],"_revision_number":2},{"id":"a4e0d80072a8eacadb5947eac53c74dc17e35139","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"date":"2026-08-20 06:15:04.000000000","message":"Hashtag added: CVE-2026-76878","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"58177acea05b08f5a1137492df3189d61908cac2","revisions":{"c4e44309c4b60dd01211a910407671bfb765636a":{"kind":"REWORK","_number":1,"created":"2026-08-19 14:11:57.000000000","uploader":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"ref":"refs/changes/05/1001505/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/watcher","ref":"refs/changes/05/1001505/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/watcher refs/changes/05/1001505/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/watcher refs/changes/05/1001505/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/watcher refs/changes/05/1001505/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/watcher refs/changes/05/1001505/1"}}},"commit":{"parents":[{"commit":"faed7f9deeda107f54975f055a56fc4ec1685c45","subject":"Merge \"Add MetricDataCache and integrate it into DataSourceBase\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/watcher/commit/faed7f9deeda107f54975f055a56fc4ec1685c45"}]}],"author":{"name":"Douglas Viroel","email":"viroel@gmail.com","date":"2026-07-28 18:19:55.000000000","tz":-180},"committer":{"name":"Douglas Viroel","email":"viroel@gmail.com","date":"2026-08-19 11:42:03.000000000","tz":-180},"subject":"Add policy enforcement to webhook trigger endpoint","message":"Add policy enforcement to webhook trigger endpoint\n\nThe webhook POST endpoint (/v1/webhooks/{audit_uuid}) was entirely\nunprotected even when [api] enable_webhooks_auth was set to True, as no\noslo_policy check was applied to the request.\n\nThis patch introduce a new webhook policy module with a webhook:trigger rule\nbacked by the new admin_or_service_api base rule (role:admin,\nrole:administrator, or role:service). The policy is enforced in the\nWebhookController.post() method when enable_webhooks_auth is enabled,\nrejecting callers that do not hold one of the required roles with HTTP 403.\nWhen enable_webhooks_auth is False the endpoint remains unauthenticated and\nno policy check is applied.\n\nCloses-Bug: #2161771\nAssisted-By: Claude Code (Sonnet 4.6)\nChange-Id: Ic56f82c6825f0dc8e83ee92a92e3c3479404252d\nSigned-off-by: Douglas Viroel \u003cviroel@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/watcher/commit/c4e44309c4b60dd01211a910407671bfb765636a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/watcher/commit/c4e44309c4b60dd01211a910407671bfb765636a"}]},"branch":"refs/heads/master"},"58177acea05b08f5a1137492df3189d61908cac2":{"kind":"REWORK","_number":2,"created":"2026-08-19 15:24:00.000000000","uploader":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"ref":"refs/changes/05/1001505/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/watcher","ref":"refs/changes/05/1001505/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/watcher refs/changes/05/1001505/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/watcher refs/changes/05/1001505/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/watcher refs/changes/05/1001505/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/watcher refs/changes/05/1001505/2"}}},"commit":{"parents":[{"commit":"faed7f9deeda107f54975f055a56fc4ec1685c45","subject":"Merge \"Add MetricDataCache and integrate it into DataSourceBase\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/watcher/commit/faed7f9deeda107f54975f055a56fc4ec1685c45"}]}],"author":{"name":"Douglas Viroel","email":"viroel@gmail.com","date":"2026-07-28 18:19:55.000000000","tz":-180},"committer":{"name":"Douglas Viroel","email":"viroel@gmail.com","date":"2026-08-19 15:22:53.000000000","tz":-180},"subject":"Add policy enforcement to webhook trigger endpoint","message":"Add policy enforcement to webhook trigger endpoint\n\nThe webhook POST endpoint (/v1/webhooks/{audit_uuid}) was entirely\nunprotected even when [api] enable_webhooks_auth was set to True, as no\noslo_policy check was applied to the request.\n\nThis patch introduce a new webhook policy module with a webhook:trigger rule\nbacked by the new admin_or_service_api base rule (role:admin,\nrole:administrator, or role:service). The policy is enforced in the\nWebhookController.post() method when enable_webhooks_auth is enabled,\nrejecting callers that do not hold one of the required roles with HTTP 403.\nWhen enable_webhooks_auth is False the endpoint remains unauthenticated and\nno policy check is applied.\n\nCloses-Bug: #2161771\nAssisted-By: Claude Code (Sonnet 4.6)\nChange-Id: Ic56f82c6825f0dc8e83ee92a92e3c3479404252d\nSigned-off-by: Douglas Viroel \u003cviroel@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/watcher/commit/58177acea05b08f5a1137492df3189d61908cac2"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/watcher/commit/58177acea05b08f5a1137492df3189d61908cac2"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},{"label":"Review-Priority","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Review-Priority","description":"Review Priority","status":"NOT_APPLICABLE","is_legacy":false,"applicability_expression_result":{"fulfilled":false,"status":"FAIL"},"submittability_expression_result":{"expression":"is:true","fulfilled":true,"status":"NOT_EVALUATED","passing_atoms":[],"failing_atoms":[],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
