)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"26911a65a1880a250ed2361bee1d2bf11e261491","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"862ccdca_88e9431d","updated":"2025-02-10 10:53:23.000000000","message":"recheck","commit_id":"3578899e7d01b705244f19d905d15310ddf71009"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"4b4cc197f7a0881560a4267bb883b4f3c636bea1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"b1862376_bdb880ad","updated":"2025-02-11 13:41:19.000000000","message":"recheck","commit_id":"dfd932cec530fddb9f434bc2467fd509351b9886"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"42596660ef9f2c96f40004137539401d29525aad","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":14,"id":"f3ca28e8_748cac66","updated":"2025-02-25 12:47:56.000000000","message":"Patchset 14 removed some changes that is not necessary in the scope of this change.","commit_id":"9b841171adb48276ca0c3548696359c261cef2b9"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"70b422b7a03c35c7a16367df88dfff9af9de7a8c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"f04a5124_c25f04b8","updated":"2025-02-25 13:04:16.000000000","message":"Patchset 15 add `oidc.default_signing_algorithm` to `SystemAttributes`","commit_id":"5ac05a1b6b9332206d0c50df1f0f20c687dd3946"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"e31a4b941e4b0f4a638bbb87320d97c61f3c0f2b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":17,"id":"fc52820e_0acaf94e","updated":"2025-02-25 13:08:11.000000000","message":"Patchset 16,17 removed unnecessary changes that is not in scope of this change.","commit_id":"9b9d517a56598555d16230325d82d6fdc9b505ed"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"e55abf049c572b3a6357d53cc77cc3b2c1345ef3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"6055c99b_d8204224","updated":"2025-02-25 14:35:22.000000000","message":"Patchset 18 further removed changes that is not necessary in the scope of this change.","commit_id":"19478696cfc6f9908d7f2f2288102344ecd29051"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"457423f064d9dd6e4c52986e639a2e0af3dc6332","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"0047e7b0_21f6add8","updated":"2025-02-26 09:35:37.000000000","message":"recheck","commit_id":"19478696cfc6f9908d7f2f2288102344ecd29051"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"a42352e05787ecc5844b3be75a2c1d4ea48c04bb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"3d035203_222f23eb","updated":"2025-02-26 06:41:05.000000000","message":"recheck","commit_id":"19478696cfc6f9908d7f2f2288102344ecd29051"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"32b9186044965fb39389a9441d825feacdb057b6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"4757bc45_c945180d","updated":"2025-02-25 17:47:27.000000000","message":"recheck","commit_id":"19478696cfc6f9908d7f2f2288102344ecd29051"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"2fd75a43fb29cd3d67bd2b9dec654b741551329b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"9163e4be_81a1ef73","updated":"2025-02-26 11:42:55.000000000","message":"recheck","commit_id":"19478696cfc6f9908d7f2f2288102344ecd29051"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"095db03c4b6992009569d3d09269af06de0001ad","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":20,"id":"3556362b_2ed597d0","updated":"2025-02-27 08:53:47.000000000","message":"recheck","commit_id":"1202d6e3de2ae931262b66c22b7a818c037be7cc"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"0d6fbf19ef94996cbfc03cf7d4632fe88ff8a757","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":20,"id":"77e61b09_f3433447","updated":"2025-02-27 06:37:53.000000000","message":"recheck","commit_id":"1202d6e3de2ae931262b66c22b7a818c037be7cc"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"8de800cdc650f8ee5e0173a1d9bf184c68cac498","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":20,"id":"ad4a5eec_6a76aa97","updated":"2025-02-27 11:21:36.000000000","message":"recheck","commit_id":"1202d6e3de2ae931262b66c22b7a818c037be7cc"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"05f5ef826948e003c71944a1ae7600e9020df7b7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":21,"id":"157745e6_1599063b","updated":"2025-03-06 11:44:05.000000000","message":"recheck","commit_id":"cd41232cc0d93cdc52880b660857c06e443ef415"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"f25a7758d34446460629459620fa1b2bc21a4ec9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":21,"id":"1e9946d6_73069963","updated":"2025-03-04 15:16:24.000000000","message":"recheck","commit_id":"cd41232cc0d93cdc52880b660857c06e443ef415"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"c1e0dfb95baab09c26286fab8d9698ee0ef190b3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":21,"id":"5595aabd_0a768d5b","updated":"2025-03-06 08:44:56.000000000","message":"recheck","commit_id":"cd41232cc0d93cdc52880b660857c06e443ef415"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"f614aee0cd63d2de3bf1db671d7f4b145dd5f529","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":21,"id":"94f18951_d628935f","updated":"2025-03-04 12:50:55.000000000","message":"recheck","commit_id":"cd41232cc0d93cdc52880b660857c06e443ef415"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"5beff9cc1574fdf86dcd748ae32a6dade733118c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":21,"id":"a8ed000f_4195b645","updated":"2025-03-07 07:34:24.000000000","message":"recheck","commit_id":"cd41232cc0d93cdc52880b660857c06e443ef415"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"5f0125071c817c161051b8186bfe15d809128736","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":25,"id":"49a70638_652e8f03","updated":"2025-04-07 06:36:41.000000000","message":"recheck","commit_id":"0d74420c0e138ad6423b8da4c5e4f8108c3b9930"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"6179188243fc3ecbac4b6f8b72e294dc694f6c5f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":31,"id":"04289229_3a57943a","updated":"2025-04-14 11:43:34.000000000","message":"recheck","commit_id":"bccfaeeeff28c21d227f98baced56cf7c4e34e36"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"7180c9fffd4f165b133581ea5f196f7007089bdf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":31,"id":"4f1b3392_99559ddc","updated":"2025-04-14 10:14:52.000000000","message":"recheck","commit_id":"bccfaeeeff28c21d227f98baced56cf7c4e34e36"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"2afd6b81041ac746324ee561e55315a0943547cf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":31,"id":"5b745890_e2e97018","updated":"2025-04-14 08:21:29.000000000","message":"recheck","commit_id":"bccfaeeeff28c21d227f98baced56cf7c4e34e36"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"a39aec4ebe9df8f312933014d5d159976b31841c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":31,"id":"aded77ea_41ec86ba","updated":"2025-04-14 09:21:59.000000000","message":"recheck","commit_id":"bccfaeeeff28c21d227f98baced56cf7c4e34e36"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"9fc5dbaf954859d8de397704756f811328a220f9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":32,"id":"a4fe1734_30d4df0f","updated":"2025-04-15 12:37:45.000000000","message":"Doc is added in a separate change here: https://review.opendev.org/c/zuul/zuul/+/941081","commit_id":"21e54e5d707efb3cf59653f9de523292ec2aee23"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"222efd4c6e72cba5a353305ab46a016f557c3d38","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":32,"id":"b38e152a_e9c2d199","updated":"2025-04-15 09:22:46.000000000","message":"recheck","commit_id":"21e54e5d707efb3cf59653f9de523292ec2aee23"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"2a024a58f879229d025241d47bd9374b70fc4f6a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":33,"id":"dc83776e_285961ce","updated":"2025-04-16 08:58:29.000000000","message":"recheck","commit_id":"1c5fad714f7b212f288b1fb24f2b6d4eb3e64131"}],"tests/fixtures/config/multi-tenant/main-reconfig.yaml":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"7c5c942b057cf4dd7c8486bd935ad39f20a0a19b","unresolved":false,"context_lines":[{"line_number":1,"context_line":"- tenant:"},{"line_number":2,"context_line":"    name: tenant-one"},{"line_number":3,"context_line":"    max-job-timeout: 1800"},{"line_number":4,"context_line":"    max-oidc-ttl: 300"},{"line_number":5,"context_line":"    allowed-reporters:"},{"line_number":6,"context_line":"      - gerrit"},{"line_number":7,"context_line":"    allowed-labels:"}],"source_content_type":"text/x-yaml","patch_set":32,"id":"12262036_5089b666","line":4,"updated":"2025-04-14 23:09:49.000000000","message":"We need docs for this.","commit_id":"21e54e5d707efb3cf59653f9de523292ec2aee23"}],"zuul/model.py":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"61a4d7efa2ddb32b305527d02601905fba23f850","unresolved":true,"context_lines":[{"line_number":9583,"context_line":"        self.name \u003d name"},{"line_number":9584,"context_line":"        self.max_nodes_per_job \u003d 5"},{"line_number":9585,"context_line":"        self.max_job_timeout \u003d 10800"},{"line_number":9586,"context_line":"        self.max_oidc_ttl \u003d 600"},{"line_number":9587,"context_line":"        self.max_changes_per_pipeline \u003d None"},{"line_number":9588,"context_line":"        self.max_dependencies \u003d None"},{"line_number":9589,"context_line":"        self.exclude_unprotected_branches \u003d False"}],"source_content_type":"text/x-python","patch_set":6,"id":"2a8b194b_08088641","line":9586,"updated":"2025-02-12 23:23:05.000000000","message":"I\u0027m not sure the default max ttl should be so small.  Perhaps 10800 (3 hours) to match the default max-job-timeout would make sense?","commit_id":"dfd932cec530fddb9f434bc2467fd509351b9886"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"a90186ee6bedf325311b1fe1117c103f30862961","unresolved":false,"context_lines":[{"line_number":9583,"context_line":"        self.name \u003d name"},{"line_number":9584,"context_line":"        self.max_nodes_per_job \u003d 5"},{"line_number":9585,"context_line":"        self.max_job_timeout \u003d 10800"},{"line_number":9586,"context_line":"        self.max_oidc_ttl \u003d 600"},{"line_number":9587,"context_line":"        self.max_changes_per_pipeline \u003d None"},{"line_number":9588,"context_line":"        self.max_dependencies \u003d None"},{"line_number":9589,"context_line":"        self.exclude_unprotected_branches \u003d False"}],"source_content_type":"text/x-python","patch_set":6,"id":"28f2fbff_0c652d85","line":9586,"in_reply_to":"2a8b194b_08088641","updated":"2025-02-13 08:33:35.000000000","message":"Acknowledged","commit_id":"dfd932cec530fddb9f434bc2467fd509351b9886"},{"author":{"_account_id":27582,"name":"Simon Westphahl","email":"simon.westphahl@bmw.de","username":"simon.westphahl"},"change_message_id":"192ba85aec7e3596c7667f56c0279909067e7cd4","unresolved":true,"context_lines":[{"line_number":8591,"context_line":""},{"line_number":8592,"context_line":"        self.oidc_supported_signing_algorithms \u003d get_default("},{"line_number":8593,"context_line":"            config, \u0027oidc\u0027, \u0027supported_signing_algorithms\u0027,"},{"line_number":8594,"context_line":"            self._default_oidc_supported_signing_algorithms)"},{"line_number":8595,"context_line":""},{"line_number":8596,"context_line":"    def toDict(self):"},{"line_number":8597,"context_line":"        return {"}],"source_content_type":"text/x-python","patch_set":12,"id":"74884224_d08da8c7","line":8594,"updated":"2025-02-24 08:37:37.000000000","message":"Should we maybe do the `str.split(\",\")` here and store this as a list of signing algos?","commit_id":"0c63efa0ed1f13e888430e8393b87320a6c5bcab"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"5af99c22a8d02ddb2a85fa9f72955908efd210d5","unresolved":false,"context_lines":[{"line_number":8591,"context_line":""},{"line_number":8592,"context_line":"        self.oidc_supported_signing_algorithms \u003d get_default("},{"line_number":8593,"context_line":"            config, \u0027oidc\u0027, \u0027supported_signing_algorithms\u0027,"},{"line_number":8594,"context_line":"            self._default_oidc_supported_signing_algorithms)"},{"line_number":8595,"context_line":""},{"line_number":8596,"context_line":"    def toDict(self):"},{"line_number":8597,"context_line":"        return {"}],"source_content_type":"text/x-python","patch_set":12,"id":"0e7e0de0_37e45768","line":8594,"in_reply_to":"74884224_d08da8c7","updated":"2025-02-24 12:24:14.000000000","message":"Yes, it makes sense. Updated in the new patch.","commit_id":"0c63efa0ed1f13e888430e8393b87320a6c5bcab"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"7c5c942b057cf4dd7c8486bd935ad39f20a0a19b","unresolved":false,"context_lines":[{"line_number":8980,"context_line":""},{"line_number":8981,"context_line":"        self.oidc_default_signing_algorithm \u003d get_default("},{"line_number":8982,"context_line":"            config, \u0027oidc\u0027, \u0027default_signing_algorithm\u0027,"},{"line_number":8983,"context_line":"            self._default_oidc_default_signing_algorithm)"},{"line_number":8984,"context_line":""},{"line_number":8985,"context_line":"    def toDict(self):"},{"line_number":8986,"context_line":"        return {"}],"source_content_type":"text/x-python","patch_set":32,"id":"e60fdb54_d265ea3c","line":8983,"updated":"2025-04-14 23:09:49.000000000","message":"We need docs for these.","commit_id":"21e54e5d707efb3cf59653f9de523292ec2aee23"}],"zuul/scheduler.py":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"61a4d7efa2ddb32b305527d02601905fba23f850","unresolved":true,"context_lines":[{"line_number":757,"context_line":""},{"line_number":758,"context_line":"            supported_algorithms \u003d ["},{"line_number":759,"context_line":"                alg.strip() for alg in self.config.get("},{"line_number":760,"context_line":"                    \u0027oidc\u0027, \u0027supported_algorithms\u0027, fallback\u003d\u0027RS256\u0027"},{"line_number":761,"context_line":"                ).split(\u0027,\u0027)"},{"line_number":762,"context_line":"            ]"},{"line_number":763,"context_line":"            # Get the rotation interval from the config, or use the default"}],"source_content_type":"text/x-python","patch_set":6,"id":"3f219480_916bf57e","line":760,"updated":"2025-02-12 23:23:05.000000000","message":"-1: I think this was \"supported_signing_algorithms\" in the spec.\n\nJust a note that in the future, we should remember to change fallback to include the other supported algorithms (all the algorithms should be supported by default).","commit_id":"dfd932cec530fddb9f434bc2467fd509351b9886"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"a90186ee6bedf325311b1fe1117c103f30862961","unresolved":false,"context_lines":[{"line_number":757,"context_line":""},{"line_number":758,"context_line":"            supported_algorithms \u003d ["},{"line_number":759,"context_line":"                alg.strip() for alg in self.config.get("},{"line_number":760,"context_line":"                    \u0027oidc\u0027, \u0027supported_algorithms\u0027, fallback\u003d\u0027RS256\u0027"},{"line_number":761,"context_line":"                ).split(\u0027,\u0027)"},{"line_number":762,"context_line":"            ]"},{"line_number":763,"context_line":"            # Get the rotation interval from the config, or use the default"}],"source_content_type":"text/x-python","patch_set":6,"id":"80fa96a6_95692a70","line":760,"in_reply_to":"3f219480_916bf57e","updated":"2025-02-13 08:33:35.000000000","message":"Acknowledged","commit_id":"dfd932cec530fddb9f434bc2467fd509351b9886"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"61a4d7efa2ddb32b305527d02601905fba23f850","unresolved":true,"context_lines":[{"line_number":768,"context_line":"            max_ttl \u003d max("},{"line_number":769,"context_line":"                self.abide.tenants.values(),"},{"line_number":770,"context_line":"                key\u003dlambda t: t.max_oidc_ttl"},{"line_number":771,"context_line":"            ).max_oidc_ttl"},{"line_number":772,"context_line":""},{"line_number":773,"context_line":"            for algorithm in supported_algorithms:"},{"line_number":774,"context_line":"                try:"}],"source_content_type":"text/x-python","patch_set":6,"id":"9f4f9273_ea0b8a5d","line":771,"updated":"2025-02-12 23:23:05.000000000","message":"Nit: possibly more idiomatic as: max(t.max_oidc_ttl for t in self.abide.tenants.values())","commit_id":"dfd932cec530fddb9f434bc2467fd509351b9886"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"a90186ee6bedf325311b1fe1117c103f30862961","unresolved":false,"context_lines":[{"line_number":768,"context_line":"            max_ttl \u003d max("},{"line_number":769,"context_line":"                self.abide.tenants.values(),"},{"line_number":770,"context_line":"                key\u003dlambda t: t.max_oidc_ttl"},{"line_number":771,"context_line":"            ).max_oidc_ttl"},{"line_number":772,"context_line":""},{"line_number":773,"context_line":"            for algorithm in supported_algorithms:"},{"line_number":774,"context_line":"                try:"}],"source_content_type":"text/x-python","patch_set":6,"id":"953eb411_d1f60c71","line":771,"in_reply_to":"9f4f9273_ea0b8a5d","updated":"2025-02-13 08:33:35.000000000","message":"Acknowledged","commit_id":"dfd932cec530fddb9f434bc2467fd509351b9886"},{"author":{"_account_id":27582,"name":"Simon Westphahl","email":"simon.westphahl@bmw.de","username":"simon.westphahl"},"change_message_id":"d61fe1b8b36f43f17d390e209f096426cca21fc4","unresolved":true,"context_lines":[{"line_number":758,"context_line":"            # TODO: When more algorithms are supported, this should be"},{"line_number":759,"context_line":"            # fallback to all supported algorithms"},{"line_number":760,"context_line":"            supported_signing_algorithms \u003d ["},{"line_number":761,"context_line":"                alg.strip() for alg in self.config.get("},{"line_number":762,"context_line":"                    \u0027oidc\u0027, \u0027supported_signing_algorithms\u0027, fallback\u003d\u0027RS256\u0027"},{"line_number":763,"context_line":"                ).split(\u0027,\u0027)"},{"line_number":764,"context_line":"            ]"}],"source_content_type":"text/x-python","patch_set":9,"id":"01d44f49_b315d8c1","line":761,"updated":"2025-02-21 13:03:22.000000000","message":"I\u0027m wondering if the signing algo and the key rotation interval should maybe be part of the `SystemAttributes`?\n\nIf there could be issues if those settings are different on multiple schedulers, the we should save/get this from the system attributes.","commit_id":"3eee5cb7681a2dff2c175879673b7b8dbfa12c74"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"ec4d9867c031f4afec3d176bb6b931dffa40ab89","unresolved":true,"context_lines":[{"line_number":758,"context_line":"            # TODO: When more algorithms are supported, this should be"},{"line_number":759,"context_line":"            # fallback to all supported algorithms"},{"line_number":760,"context_line":"            supported_signing_algorithms \u003d ["},{"line_number":761,"context_line":"                alg.strip() for alg in self.config.get("},{"line_number":762,"context_line":"                    \u0027oidc\u0027, \u0027supported_signing_algorithms\u0027, fallback\u003d\u0027RS256\u0027"},{"line_number":763,"context_line":"                ).split(\u0027,\u0027)"},{"line_number":764,"context_line":"            ]"}],"source_content_type":"text/x-python","patch_set":9,"id":"8f24b722_cfccf22c","line":761,"in_reply_to":"01d44f49_b315d8c1","updated":"2025-02-21 14:16:39.000000000","message":"Good point.\n\nFor different configurations among the schedulers, it should be actually ok:\n- If the `supported_signing_algorithms` are configured differently on different schedulers, each scheduler would check and rotate the signing keys of the algorithms configured on that scheduler, and in the end the union of the all algorithms would be checked for rotation hourly. \n- If the \u0027signing_key_rotation_interval\u0027 are configured differently on different schedulers, for each algorithm, the smallest \u0027signing_key_rotation_interval\u0027 configured on the same scheduler would have the final effect, i.e. it would be rotated as soon as possible.\n\n\nHow ever, if zuul-web have a different configuration than the scheduler, there would be problems:\n- When the `supported_signing_algorithms` in zuul-web is not configured in zuul-scheduler, those missing algorithms would not be rotated.\n- When other way round, the public signing keys for the algorithms missed on zuul-web configuration would not be available in /jwks endpoint, and the tokens signed by that algorithm can not be validated.\n\nSo I think yes, we should move them to `SystemAttributes` to make sure they are consistent across the components.","commit_id":"3eee5cb7681a2dff2c175879673b7b8dbfa12c74"},{"author":{"_account_id":33134,"name":"Dong Zhang","email":"dong.zhang@bmw.de","username":"dongzhang"},"change_message_id":"5af99c22a8d02ddb2a85fa9f72955908efd210d5","unresolved":false,"context_lines":[{"line_number":758,"context_line":"            # TODO: When more algorithms are supported, this should be"},{"line_number":759,"context_line":"            # fallback to all supported algorithms"},{"line_number":760,"context_line":"            supported_signing_algorithms \u003d ["},{"line_number":761,"context_line":"                alg.strip() for alg in self.config.get("},{"line_number":762,"context_line":"                    \u0027oidc\u0027, \u0027supported_signing_algorithms\u0027, fallback\u003d\u0027RS256\u0027"},{"line_number":763,"context_line":"                ).split(\u0027,\u0027)"},{"line_number":764,"context_line":"            ]"}],"source_content_type":"text/x-python","patch_set":9,"id":"65460e9b_3d786310","line":761,"in_reply_to":"8f24b722_cfccf22c","updated":"2025-02-24 12:24:14.000000000","message":"Done","commit_id":"3eee5cb7681a2dff2c175879673b7b8dbfa12c74"}]}
