)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":1004,"name":"Mohammed Naser","email":"mnaser@vexxhost.com","username":"mnaser"},"change_message_id":"5de078290963d84d028c74ca20b1c70f3fa29ae5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"5cea273d_b0d8722e","updated":"2025-11-30 02:31:20.000000000","message":"Just my 2 cents.. I know this is quite the reach but it would be nice if the gap could be bridged between SCM and Zuul.\n\nFor example, if I don\u0027t have access to a specific project in GitHub (or Gerrit), then I cannot view jobs for it in the UI.\n\nI am not sure on how all that could be wired up, but it can be huge.  It\u0027s currently making us have to run several tenants unnecessarily so simply to create some compartments of who can see what.\n\nIf based on GitHub or Gerrit permissions, it would allow you to view jobs/etc, that would be _quite neat_, but I can imagine a lot of work.","commit_id":"639963e22257f2eb5fc5624b7a8794739dfd6e92"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"92978259ff98c638b6ac534bff3e3d786feecea9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"fb3cf247_b4586de0","in_reply_to":"5cea273d_b0d8722e","updated":"2025-12-02 22:36:49.000000000","message":"While this spec does touch on some ability to restrict access by project (specifically so that permissions like enqueue can be allocated to people with access to that project (in principle, aligning the access to *re-enqueue* a change to the same access for the original enqueuing of the change)), I don\u0027t anticipate changing the model for job visibility and access.  The purpose of a tenant is to scope access to shared resources (like jobs and pipelines) across projects, and if those projects have no interaction, it is proper for them to have a separate tenant.  Tenants are relatively cheap in Zuul, and indeed, there are few downsides and many upsides to having more of them.","commit_id":"639963e22257f2eb5fc5624b7a8794739dfd6e92"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"faa18f3511f9396fe1160f31d3fb2f97bed675a6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"0066e2b2_eb9605e0","updated":"2025-12-04 02:35:11.000000000","message":"Patchset 3 was a trivial rebase to address a merge conflict in the spec index after the init-jobs spec merged. I\u0027m carrying over my +2 as a result.","commit_id":"07f333ff85cfded876c247b3b543423866e3008d"}],"doc/source/developer/specs/web-rbac.rst":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"c0f6d0dd7a7cfd44dc9db036d314b9ea8c6104ea","unresolved":true,"context_lines":[{"line_number":87,"context_line":"         enqueue:"},{"line_number":88,"context_line":"           conditions:"},{"line_number":89,"context_line":"             pipeline: post"},{"line_number":90,"context_line":"             project: foo"},{"line_number":91,"context_line":""},{"line_number":92,"context_line":"   - tenant:"},{"line_number":93,"context_line":"       name: example"}],"source_content_type":"text/x-rst","patch_set":2,"id":"3c3940b8_67401ff3","line":90,"updated":"2025-11-21 01:08:17.000000000","message":"Just want to note that controlling both the pipeline and project here is likely an important feature to doing this safely. I reenqueued a buildset (as admin) the other day and realized that for post merge actions idempotency is important and understanding what is safe is often project and pipeline specific. The ability to restrict reenqueuing things ensures that we can limit the functionality to people who understand these concerns within their domain and don\u0027t accidentally allow too much access in different domains.","commit_id":"639963e22257f2eb5fc5624b7a8794739dfd6e92"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"c0f6d0dd7a7cfd44dc9db036d314b9ea8c6104ea","unresolved":true,"context_lines":[{"line_number":159,"context_line":"expected that every zuul-web API endpoint that is currently protected"},{"line_number":160,"context_line":"by `admin` access will have a unique permission, and that generally,"},{"line_number":161,"context_line":"if those endpoints accept user input (such as project names), we will"},{"line_number":162,"context_line":"try to make conditions available for them as well.  Any variances from"},{"line_number":163,"context_line":"this can be discussed in the implementing changes."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"Alternatives"}],"source_content_type":"text/x-rst","patch_set":2,"id":"98c4759e_1713a795","line":162,"range":{"start_line":162,"start_character":0,"end_line":162,"end_character":49},"updated":"2025-11-21 01:08:17.000000000","message":"Do we think we will apply some sort of wildcard or regex matching to the conditions?","commit_id":"639963e22257f2eb5fc5624b7a8794739dfd6e92"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"f8a6cd8f2ced95f3b6276fc85ce7154dd11dee25","unresolved":false,"context_lines":[{"line_number":159,"context_line":"expected that every zuul-web API endpoint that is currently protected"},{"line_number":160,"context_line":"by `admin` access will have a unique permission, and that generally,"},{"line_number":161,"context_line":"if those endpoints accept user input (such as project names), we will"},{"line_number":162,"context_line":"try to make conditions available for them as well.  Any variances from"},{"line_number":163,"context_line":"this can be discussed in the implementing changes."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"Alternatives"}],"source_content_type":"text/x-rst","patch_set":2,"id":"79648a58_bbc8b49b","line":162,"in_reply_to":"98c4759e_1713a795","updated":"2025-11-21 18:42:12.000000000","message":"That sounds reasonable to me.","commit_id":"639963e22257f2eb5fc5624b7a8794739dfd6e92"}]}
