)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"14fb35db7c2d194d3506a08388c1f5ae02098db7","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"8d74e42a_d8d7e489","updated":"2026-07-28 19:04:33.000000000","message":"-1 is becasue i think if we change this we shoudl also add a note to the api ref to deicbe the use of the header\n\ni think the change is fine as is beyond that","commit_id":"98210cb16ca077e4f640c404e5aaddff970b397b"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"604f942c02267efad44a7ff32926addf2d101497","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"9dada828_7fb34c5b","updated":"2026-07-29 03:21:35.000000000","message":"While digging into the code I noticed there is not real soft-delete mechanism within watcher and all objects are direct deleted by the deleted query... We should probably rather remove the header if this has never been implemented correctly.","commit_id":"98210cb16ca077e4f640c404e5aaddff970b397b"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"34c1c11cc625af94aafaea66652050e93d2f5124","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"be1def54_017ceb87","in_reply_to":"9dada828_7fb34c5b","updated":"2026-07-29 03:23:59.000000000","message":"Nevermind. I didn\u0027t notice that there is a separate api for soft_delete.","commit_id":"98210cb16ca077e4f640c404e5aaddff970b397b"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"1f1d941967a4b61908625804c32f59e4ac5797ba","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"353c021a_ac429677","in_reply_to":"be1def54_017ceb87","updated":"2026-07-29 12:17:51.000000000","message":"https://github.com/openstack/watcher/blob/master/watcher/db/sqlalchemy/models.py#L93 its provide via the mixin\n\nall deletes are soft deleted and then purged later","commit_id":"98210cb16ca077e4f640c404e5aaddff970b397b"}],"releasenotes/notes/bug-2161911-dbecdf0af925ec41.yaml":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"b712a775a17370d109fbd5bd2add5c7ab3fbb786","unresolved":false,"context_lines":[{"line_number":4,"context_line":"    `Bug 2161911 \u003chttps://bugs.launchpad.net/watcher/+bug/2161911\u003e`_: Fixed"},{"line_number":5,"context_line":"    the ``X-Show-Deleted`` header does not recognize the provided value. Now"},{"line_number":6,"context_line":"    only ``1``, ``t``, ``true``, ``on``, ``y`` and ``yes`` are treated as"},{"line_number":7,"context_line":"    ``True`` (case-insensitive), and other thean them are treated as ``False``."}],"source_content_type":"text/x-yaml","patch_set":3,"id":"8e8ea353_c405b6ff","line":7,"updated":"2026-07-27 17:09:01.000000000","message":"The release note for bug 2161911 contains a spelling error: \u0027other thean them\u0027 should read \u0027other than them\u0027. This typo is in the user-facing release notes.\n\n**Severity**: SUGGESTION | **Confidence**: 1.0\n\n**Benefit**: The release note is user-facing documentation that will be published. A spelling error reduces clarity and professionalism of the documentation.\n\n**Recommendation**:\nChange \u0027other thean them\u0027 to \u0027other than them\u0027 in the release note.","commit_id":"2de403cda4effc977856ef0cd901c48e0c72b1ca"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"410d7e1ed210321e416146001c354c803ab9fc0e","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"fixes:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    `Bug 2161911 \u003chttps://bugs.launchpad.net/watcher/+bug/2161911\u003e`_: Fixed"},{"line_number":5,"context_line":"    the ``X-Show-Deleted`` header does not recognize the provided value. Now"},{"line_number":6,"context_line":"    only ``1``, ``t``, ``true``, ``on``, ``y`` and ``yes`` are treated as"},{"line_number":7,"context_line":"    ``True`` (case-insensitive), and other thean them are treated as ``False``."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"d9cb2411_0d2b1f97","line":4,"updated":"2026-07-28 15:16:32.000000000","message":"The release note for bug 2161911 contains a typo (\u0027thean\u0027 instead of \u0027than\u0027) and an awkward sentence structure (\u0027Fixed the X-Show-Deleted header does not recognize the provided value\u0027) that will confuse operators reading release notes.\n\n**Severity**: SUGGESTION | **Confidence**: 0.9\n\n**Benefit**: Operators reading the release note will encounter a typo and confusing sentence structure, reducing clarity of the fix description.\n\n**Recommendation**:\nFix the typo \u0027thean\u0027 → \u0027than\u0027 and rephrase the opening sentence to read naturally, e.g., \u0027Fixed an issue where the ``X-Show-Deleted`` header did not recognize the provided value.\u0027","commit_id":"98210cb16ca077e4f640c404e5aaddff970b397b"}],"watcher/api/hooks.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"003efd00019b6fc9359af430d20c17e10e56dda2","unresolved":false,"context_lines":[{"line_number":27,"context_line":"    \"\"\"Configures a request context and attaches it to the request.\"\"\""},{"line_number":28,"context_line":""},{"line_number":29,"context_line":"    def before(self, state):"},{"line_number":30,"context_line":"        show_deleted \u003d strutils.bool_from_string("},{"line_number":31,"context_line":"            state.request.headers.get(\u0027X-Show-Deleted\u0027)"},{"line_number":32,"context_line":"        )"},{"line_number":33,"context_line":"        state.request.context \u003d context.RequestContext.from_environ("}],"source_content_type":"text/x-python","patch_set":1,"id":"7cc33fe9_afa64fe8","line":30,"updated":"2026-06-30 17:38:24.000000000","message":"bool_from_string is called without strict\u003dTrue, so malformed values such as \u0027flase\u0027, \u0027tru\u0027, or arbitrary garbage silently evaluate to True (the non-strict default). This is the same class of unexpected-truthiness bug being fixed here, just for malformed rather than negative input.\n\n**Severity**: SUGGESTION | **Confidence**: 0.8\n\n**Benefit**: Rejecting unrecognized header values with strict\u003dTrue mirrors the existing BooleanType.validate pattern in this project (watcher/api/controllers/v1/types.py:115 uses strict\u003dTrue and maps ValueError to a 400 Invalid). It would prevent a typoed header from unexpectedly exposing soft-deleted resources.\n\n**Recommendation**:\nConsider passing strict\u003dTrue and wrapping the call so a ValueError yields a 400 BadRequest response, consistent with types.py. If silent defaulting is intentionally preferred for backward compatibility, add a brief comment documenting that decision so the choice is explicit.","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"14fb35db7c2d194d3506a08388c1f5ae02098db7","unresolved":true,"context_lines":[{"line_number":27,"context_line":"    \"\"\"Configures a request context and attaches it to the request.\"\"\""},{"line_number":28,"context_line":""},{"line_number":29,"context_line":"    def before(self, state):"},{"line_number":30,"context_line":"        show_deleted \u003d strutils.bool_from_string("},{"line_number":31,"context_line":"            state.request.headers.get(\u0027X-Show-Deleted\u0027)"},{"line_number":32,"context_line":"        )"},{"line_number":33,"context_line":"        state.request.context \u003d context.RequestContext.from_environ("}],"source_content_type":"text/x-python","patch_set":1,"id":"f190aed2_e362613c","line":30,"in_reply_to":"04f29cda_e0538251","updated":"2026-07-28 19:04:33.000000000","message":"i dont think we need strict, we could but im more concerd about the fact that this is not docuemanted as supproted at all\n\n\nhttps://docs.openstack.org/api-ref/resource-optimization/#list-goal list gals has test for this but its not in the api ref\n\nwe would also normally use a queary arg to contole this","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d7154425e97c7965cf970cf7a411bb7d55a91011","unresolved":true,"context_lines":[{"line_number":27,"context_line":"    \"\"\"Configures a request context and attaches it to the request.\"\"\""},{"line_number":28,"context_line":""},{"line_number":29,"context_line":"    def before(self, state):"},{"line_number":30,"context_line":"        show_deleted \u003d strutils.bool_from_string("},{"line_number":31,"context_line":"            state.request.headers.get(\u0027X-Show-Deleted\u0027)"},{"line_number":32,"context_line":"        )"},{"line_number":33,"context_line":"        state.request.context \u003d context.RequestContext.from_environ("}],"source_content_type":"text/x-python","patch_set":1,"id":"04f29cda_e0538251","line":30,"in_reply_to":"315dd9f8_ddfa8eca","updated":"2026-07-27 17:04:14.000000000","message":"I didn\u0027t add string\u003dtrue following the existing implementations in the other projects such as deleted query parameter in nova, but have not very strong opinion about it.\nI\u0027d keep this open to hear further inputs and decide which we prefer.","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"},{"author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"change_message_id":"e6c0f6ae0c059b009554757885de0c4b480afc06","unresolved":true,"context_lines":[{"line_number":27,"context_line":"    \"\"\"Configures a request context and attaches it to the request.\"\"\""},{"line_number":28,"context_line":""},{"line_number":29,"context_line":"    def before(self, state):"},{"line_number":30,"context_line":"        show_deleted \u003d strutils.bool_from_string("},{"line_number":31,"context_line":"            state.request.headers.get(\u0027X-Show-Deleted\u0027)"},{"line_number":32,"context_line":"        )"},{"line_number":33,"context_line":"        state.request.context \u003d context.RequestContext.from_environ("}],"source_content_type":"text/x-python","patch_set":1,"id":"315dd9f8_ddfa8eca","line":30,"in_reply_to":"7cc33fe9_afa64fe8","updated":"2026-07-24 12:07:53.000000000","message":"this seems valid","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"}],"watcher/tests/unit/api/v1/test_actions.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"003efd00019b6fc9359af430d20c17e10e56dda2","unresolved":false,"context_lines":[{"line_number":187,"context_line":"        )"},{"line_number":188,"context_line":"        self.assertEqual(HTTPStatus.NOT_FOUND, response.status_int)"},{"line_number":189,"context_line":""},{"line_number":190,"context_line":"        # NOTE(tkajinam): This is an only example test case for negative"},{"line_number":191,"context_line":"        # X-Show-Deleted header values."},{"line_number":192,"context_line":"        response \u003d self.get_json("},{"line_number":193,"context_line":"            \u0027/actions/{}\u0027.format(action[\u0027uuid\u0027]),"}],"source_content_type":"text/x-python","patch_set":1,"id":"ec5fdeab_97ecd6b2","line":190,"updated":"2026-06-30 17:38:24.000000000","message":"The new assertions are appended to the existing test_show_soft_deleted method, which already mixes positive and negative scenarios. The NOTE comment frames the block as an example case for negative header values, indicating a separate scenario that was not split into its own test method.\n\n**Severity**: WARNING | **Confidence**: 0.8\n\n**Impact**: Combining unrelated scenarios in one method makes a failure ambiguous (which assertion failed?) and complicates adding further negative-value cases. The existing method name \u0027test_show_soft_deleted\u0027 does not convey the extra coverage.\n\n**Suggestion**:\nExtract the negative-header coverage into a dedicated test method such as test_show_soft_deleted_with_false_header, leaving test_show_soft_deleted focused on the original positive/no-header scenario.","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"003efd00019b6fc9359af430d20c17e10e56dda2","unresolved":false,"context_lines":[{"line_number":187,"context_line":"        )"},{"line_number":188,"context_line":"        self.assertEqual(HTTPStatus.NOT_FOUND, response.status_int)"},{"line_number":189,"context_line":""},{"line_number":190,"context_line":"        # NOTE(tkajinam): This is an only example test case for negative"},{"line_number":191,"context_line":"        # X-Show-Deleted header values."},{"line_number":192,"context_line":"        response \u003d self.get_json("},{"line_number":193,"context_line":"            \u0027/actions/{}\u0027.format(action[\u0027uuid\u0027]),"}],"source_content_type":"text/x-python","patch_set":1,"id":"34d63a8a_6aa9f8db","line":190,"updated":"2026-06-30 17:38:24.000000000","message":"The new test block does not exercise the negative X-Show-Deleted values the bug was about. \u0027false\u0027/\u00270\u0027/\u0027no\u0027 are not asserted anywhere; only the empty string is covered, and the added \u0027True\u0027 case duplicates the assertion at lines 178-183, leaving the actual regression unguarded.\n\n**Severity**: WARNING | **Confidence**: 0.9\n\n**Impact**: A future change that reverts the bool_from_string conversion could pass this test suite while silently re-introducing the original bug, because no test asserts that \u0027false\u0027 yields show_deleted\u003dFalse.\n\n**Suggestion**:\nReplace the redundant \u0027True\u0027 block with an assertion using \u0027false\u0027 (e.g. headers\u003d{\u0027X-Show-Deleted\u0027: \u0027false\u0027} expecting NOT_FOUND), and ideally also cover \u00270\u0027 and \u0027no\u0027. This directly locks in the behavior the fix is meant to guarantee.","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"},{"author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"change_message_id":"e6c0f6ae0c059b009554757885de0c4b480afc06","unresolved":true,"context_lines":[{"line_number":187,"context_line":"        )"},{"line_number":188,"context_line":"        self.assertEqual(HTTPStatus.NOT_FOUND, response.status_int)"},{"line_number":189,"context_line":""},{"line_number":190,"context_line":"        # NOTE(tkajinam): This is an only example test case for negative"},{"line_number":191,"context_line":"        # X-Show-Deleted header values."},{"line_number":192,"context_line":"        response \u003d self.get_json("},{"line_number":193,"context_line":"            \u0027/actions/{}\u0027.format(action[\u0027uuid\u0027]),"}],"source_content_type":"text/x-python","patch_set":1,"id":"65ef111c_d2aa11aa","line":190,"in_reply_to":"34d63a8a_6aa9f8db","updated":"2026-07-24 12:07:53.000000000","message":"+1 for adding coverage for these cases","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d7154425e97c7965cf970cf7a411bb7d55a91011","unresolved":false,"context_lines":[{"line_number":187,"context_line":"        )"},{"line_number":188,"context_line":"        self.assertEqual(HTTPStatus.NOT_FOUND, response.status_int)"},{"line_number":189,"context_line":""},{"line_number":190,"context_line":"        # NOTE(tkajinam): This is an only example test case for negative"},{"line_number":191,"context_line":"        # X-Show-Deleted header values."},{"line_number":192,"context_line":"        response \u003d self.get_json("},{"line_number":193,"context_line":"            \u0027/actions/{}\u0027.format(action[\u0027uuid\u0027]),"}],"source_content_type":"text/x-python","patch_set":1,"id":"e2181de7_31056860","line":190,"in_reply_to":"65ef111c_d2aa11aa","updated":"2026-07-27 17:04:14.000000000","message":"Done","commit_id":"4927fa2862c8ee7686a1fc6d9ff2d1ece32df156"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"cc8b8c1ba021eddbed5eeeeea0b0d3928201ab05","unresolved":false,"context_lines":[{"line_number":196,"context_line":"        self.assertEqual(action.uuid, response[\u0027uuid\u0027])"},{"line_number":197,"context_line":"        self._assert_action_fields(response)"},{"line_number":198,"context_line":""},{"line_number":199,"context_line":"        response \u003d self.get_json("},{"line_number":200,"context_line":"            \u0027/actions/{}\u0027.format(action[\u0027uuid\u0027]),"},{"line_number":201,"context_line":"            headers\u003d{\u0027X-Show-Deleted\u0027: \u0027\u0027},"},{"line_number":202,"context_line":"            expect_errors\u003dTrue,"}],"source_content_type":"text/x-python","patch_set":2,"id":"0edae235_61a0a9df","line":199,"updated":"2026-07-27 16:49:58.000000000","message":"The added test uses X-Show-Deleted: \u0027\u0027 (empty string) as the negative case, but an empty string was already falsy before the fix. The real bug — string values like \u0027false\u0027, \u0027False\u0027, or \u00270\u0027 being incorrectly treated as truthy — is never exercised by this test.\n\n**Severity**: WARNING | **Confidence**: 0.9\n\n**Impact**: The test gives false confidence that the bug is covered. A future regression reintroducing the raw-string behavior would still pass this test, leaving the actual vulnerability unguarded.\n\n**Suggestion**:\nAdd or replace the negative test case with a header value like \u0027false\u0027 or \u0027False\u0027 that was truthy under the old code and is correctly False after the fix. For example: headers\u003d{\u0027X-Show-Deleted\u0027: \u0027false\u0027} with expect_errors\u003dTrue asserting HTTPStatus.NOT_FOUND.","commit_id":"9dc8593ebfe879334249b1f2e1d273c6acb62d4d"}]}
