*** thorst_afk has joined #openstack-keystone | 00:00 | |
*** catintheroof has joined #openstack-keystone | 00:00 | |
*** catintheroof has quit IRC | 00:01 | |
*** harlowja has quit IRC | 00:04 | |
*** catintheroof has joined #openstack-keystone | 00:04 | |
*** lamt has joined #openstack-keystone | 00:08 | |
*** dave-mccowan has quit IRC | 00:13 | |
*** lamt has quit IRC | 00:16 | |
*** lamt has joined #openstack-keystone | 00:16 | |
*** esp has left #openstack-keystone | 00:18 | |
*** browne has joined #openstack-keystone | 00:33 | |
*** catintheroof has quit IRC | 00:33 | |
*** thorst_afk has quit IRC | 00:37 | |
*** catintheroof has joined #openstack-keystone | 00:39 | |
*** markvoelker has quit IRC | 00:41 | |
*** markvoelker has joined #openstack-keystone | 00:42 | |
*** thorst_afk has joined #openstack-keystone | 00:44 | |
*** thorst_afk has quit IRC | 00:46 | |
*** dave-mccowan has joined #openstack-keystone | 00:46 | |
*** markvoelker has quit IRC | 00:46 | |
*** esp has joined #openstack-keystone | 00:46 | |
*** esp has left #openstack-keystone | 00:54 | |
*** browne has quit IRC | 00:56 | |
*** catintheroof has quit IRC | 01:09 | |
*** agrebennikov has joined #openstack-keystone | 01:10 | |
*** felipemonteiro has joined #openstack-keystone | 01:20 | |
felipemonteiro | I'm getting a 404 Not Found when I run "openstack --os-identity-api-version 2 --debug role list" using the absolutely latest version of devstack in my local env. | 01:21 |
---|---|---|
*** Shunli has joined #openstack-keystone | 01:24 | |
*** ducttape_ has joined #openstack-keystone | 01:31 | |
*** felipemonteiro has quit IRC | 01:31 | |
*** ducttape_ has quit IRC | 01:36 | |
*** nicolasbock has quit IRC | 01:41 | |
gcb | lbragstad: your comments in https://review.openstack.org/#/c/460879/1 makes sense, let's just use default value None | 01:45 |
*** felipemonteiro has joined #openstack-keystone | 01:45 | |
*** thorst_afk has joined #openstack-keystone | 01:47 | |
*** prashkre has joined #openstack-keystone | 01:48 | |
*** zhurong has joined #openstack-keystone | 01:50 | |
*** thorst_afk has quit IRC | 01:52 | |
*** nicolasbock has joined #openstack-keystone | 01:55 | |
*** jamielennox is now known as jamielennox|away | 02:03 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Fix test_minimum_password_age_and_password_expires_days_deactivated https://review.openstack.org/460879 | 02:04 |
clarkb | felipemonteiro: I think it may be v3 only by default | 02:05 |
clarkb | so you get a 404 as v2 isnt there | 02:06 |
*** ducttape_ has joined #openstack-keystone | 02:07 | |
*** zhurong has quit IRC | 02:07 | |
*** Shunli has quit IRC | 02:10 | |
felipemonteiro | clarkb: curl -g -i -X GET http://127.0.0.1/identity/v2.0/users -H "User-Agent: python-keystoneclient" -H "Accept: application/json" -H "X-Auth-Token: $TOKEN" | 02:11 |
felipemonteiro | ^ Also results in 404 for me. | 02:11 |
clarkb | thats still v2 right? | 02:12 |
clarkb | pretty sure there is no v2 by default | 02:12 |
clarkb | does v3 work? | 02:15 |
felipemonteiro | Well, "tox -eall -- tempest.api.identity.admin.v2.test_users" fails as well when manually setting CONF.identity-feature-enabled.api_v2_admin = True | 02:16 |
felipemonteiro | And yes, it works for v3. | 02:16 |
felipemonteiro | Because otherwise those tests skip. | 02:16 |
*** nicolasbock has quit IRC | 02:17 | |
*** jamielennox|away is now known as jamielennox | 02:17 | |
clarkb | right I think you may need to enable v2 in devsta k | 02:17 |
felipemonteiro | Interesting, thanks, that was my hunch | 02:18 |
felipemonteiro | I'll bet that works | 02:18 |
*** blake has quit IRC | 02:19 | |
felipemonteiro | I just figured it was enabled by default; I've never had to set ENABLE_IDENTITY_V2 to True | 02:21 |
openstackgerrit | huangtianhua proposed openstack/keystone master: Role name is unique within the owning domain https://review.openstack.org/457835 | 02:31 |
*** ducttape_ has quit IRC | 02:31 | |
*** nicolasbock has joined #openstack-keystone | 02:33 | |
*** dave-mccowan has quit IRC | 02:36 | |
*** prashkre has quit IRC | 02:43 | |
*** thorst_afk has joined #openstack-keystone | 02:48 | |
*** agrebennikov has quit IRC | 02:54 | |
*** gcb has quit IRC | 02:59 | |
*** agrebennikov has joined #openstack-keystone | 03:07 | |
*** thorst_afk has quit IRC | 03:08 | |
*** nicolasbock has quit IRC | 03:10 | |
*** gcb has joined #openstack-keystone | 03:12 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Fix keystone.tests.unit.test_v3_oauth1.MaliciousOAuth1Tests https://review.openstack.org/461279 | 03:15 |
*** gagehugo has quit IRC | 03:15 | |
*** gagehugo has joined #openstack-keystone | 03:18 | |
*** felipemonteiro has quit IRC | 03:24 | |
*** zhurong has joined #openstack-keystone | 03:37 | |
*** zhurong has quit IRC | 03:40 | |
*** masber has quit IRC | 03:46 | |
*** links has joined #openstack-keystone | 03:49 | |
*** markvoelker has joined #openstack-keystone | 04:00 | |
*** thorst_afk has joined #openstack-keystone | 04:04 | |
*** thorst_afk has quit IRC | 04:09 | |
*** agrebennikov has quit IRC | 04:18 | |
*** gagehugo has quit IRC | 04:22 | |
*** gyee has quit IRC | 04:23 | |
*** chlong has joined #openstack-keystone | 04:23 | |
*** gagehugo has joined #openstack-keystone | 04:26 | |
*** gagehugo has quit IRC | 04:27 | |
*** gagehugo has joined #openstack-keystone | 04:29 | |
*** ducttape_ has joined #openstack-keystone | 04:32 | |
*** Shunli has joined #openstack-keystone | 04:34 | |
*** aojea has joined #openstack-keystone | 04:36 | |
*** ducttape_ has quit IRC | 04:36 | |
*** zhurong has joined #openstack-keystone | 04:37 | |
*** blake has joined #openstack-keystone | 04:40 | |
*** aojea has quit IRC | 04:40 | |
*** blake has quit IRC | 04:46 | |
*** namnh has joined #openstack-keystone | 04:47 | |
*** Shunli has quit IRC | 05:01 | |
*** Shunli has joined #openstack-keystone | 05:02 | |
*** zsli_ has joined #openstack-keystone | 05:08 | |
*** Shunli has quit IRC | 05:08 | |
*** gcb has quit IRC | 05:10 | |
*** aojea has joined #openstack-keystone | 05:14 | |
*** phalmos has quit IRC | 05:14 | |
bigjools | why would I get a "Invalid user token" in the server log when specifying `openstack --os-token foo` when I have admin_token set in keystone.conf? | 05:23 |
bigjools | the paste pipeline has got the admin_token_auth filter in it | 05:25 |
*** gcb has joined #openstack-keystone | 05:27 | |
*** namnh_ has joined #openstack-keystone | 05:32 | |
*** namnh has quit IRC | 05:35 | |
*** zsli_ is now known as Shunli | 05:37 | |
*** richm has quit IRC | 05:44 | |
*** blake has joined #openstack-keystone | 05:47 | |
*** aojea has quit IRC | 05:52 | |
*** masber has joined #openstack-keystone | 05:58 | |
*** thorst_afk has joined #openstack-keystone | 06:06 | |
*** thorst_afk has quit IRC | 06:11 | |
*** tovin07 has joined #openstack-keystone | 06:12 | |
*** jaosorior_away is now known as jaosorior | 06:19 | |
*** gongysh has joined #openstack-keystone | 06:21 | |
*** voelzmo has joined #openstack-keystone | 06:26 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Test config option 'user_enabled_default' with string type value https://review.openstack.org/462001 | 06:26 |
*** pcaruana has joined #openstack-keystone | 06:27 | |
*** Aqsam has joined #openstack-keystone | 06:42 | |
*** mguiney has joined #openstack-keystone | 06:46 | |
*** Aqsam has quit IRC | 06:46 | |
openstackgerrit | zhengliuyang proposed openstack/keystone master: Remove X-Auth-Token from response parameters https://review.openstack.org/462008 | 06:47 |
*** thorst_afk has joined #openstack-keystone | 07:06 | |
openstackgerrit | Hemanth Nakkina proposed openstack/keystone master: Change url passed to oauth signature verifier to request url https://review.openstack.org/461736 | 07:07 |
*** toddnni has joined #openstack-keystone | 07:08 | |
*** blake has quit IRC | 07:10 | |
*** namnh has joined #openstack-keystone | 07:10 | |
*** thorst_afk has quit IRC | 07:11 | |
*** namnh_ has quit IRC | 07:12 | |
*** aojea has joined #openstack-keystone | 07:23 | |
*** zhurong has quit IRC | 07:24 | |
*** bjolo has joined #openstack-keystone | 07:31 | |
*** zhurong has joined #openstack-keystone | 07:43 | |
*** adriant has quit IRC | 07:43 | |
*** gongysh has quit IRC | 07:55 | |
*** masber has quit IRC | 07:56 | |
*** masber has joined #openstack-keystone | 07:59 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** thorst_afk has joined #openstack-keystone | 08:07 | |
*** thorst_afk has quit IRC | 08:26 | |
*** markvoelker has quit IRC | 08:32 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Stop using oslotest.mockpatch https://review.openstack.org/462033 | 08:41 |
*** ducttape_ has joined #openstack-keystone | 08:43 | |
*** zhurong has quit IRC | 08:47 | |
*** ducttape_ has quit IRC | 08:47 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/python-keystoneclient master: Stop using oslotest.mockpatch https://review.openstack.org/462038 | 08:51 |
*** namnh_ has joined #openstack-keystone | 08:56 | |
*** namnh has quit IRC | 08:59 | |
*** namnh has joined #openstack-keystone | 08:59 | |
*** namnh_ has quit IRC | 09:01 | |
*** zhurong has joined #openstack-keystone | 09:01 | |
*** namnh_ has joined #openstack-keystone | 09:07 | |
*** namnh has quit IRC | 09:09 | |
*** namnh has joined #openstack-keystone | 09:14 | |
*** namnh_ has quit IRC | 09:16 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Test config option 'user_enabled_default' with string type value https://review.openstack.org/462001 | 09:21 |
*** thorst_afk has joined #openstack-keystone | 09:24 | |
*** thorst_afk has quit IRC | 09:28 | |
*** jose-phi_ has joined #openstack-keystone | 09:29 | |
*** jose-phillips has quit IRC | 09:31 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Test config option 'user_enabled_default' with string type value https://review.openstack.org/462001 | 09:33 |
*** markvoelker has joined #openstack-keystone | 09:33 | |
*** Shunli has quit IRC | 09:35 | |
*** markvoelker has quit IRC | 09:38 | |
*** lamt has quit IRC | 09:40 | |
*** zhurong has quit IRC | 09:41 | |
*** namnh_ has joined #openstack-keystone | 09:46 | |
*** namnh has quit IRC | 09:49 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Fix keystone.tests.unit.test_v3_oauth1.MaliciousOAuth1Tests https://review.openstack.org/461279 | 09:56 |
*** tesseract has joined #openstack-keystone | 09:56 | |
*** gcb has quit IRC | 10:04 | |
*** zhurong has joined #openstack-keystone | 10:19 | |
*** richm has joined #openstack-keystone | 10:19 | |
*** mvk has quit IRC | 10:22 | |
*** richm has quit IRC | 10:23 | |
*** namnh has joined #openstack-keystone | 10:27 | |
*** nicolasbock has joined #openstack-keystone | 10:28 | |
*** namnh_ has quit IRC | 10:30 | |
*** zhurong has quit IRC | 10:30 | |
*** namnh_ has joined #openstack-keystone | 10:33 | |
*** markvoelker has joined #openstack-keystone | 10:34 | |
*** namnh has quit IRC | 10:36 | |
*** richm has joined #openstack-keystone | 10:38 | |
*** markvoelker has quit IRC | 10:40 | |
*** namnh has joined #openstack-keystone | 10:40 | |
*** namnh_ has quit IRC | 10:42 | |
*** namnh_ has joined #openstack-keystone | 10:43 | |
*** namnh has quit IRC | 10:46 | |
*** namnh_ has quit IRC | 11:05 | |
*** raildo has joined #openstack-keystone | 11:06 | |
*** mvk has joined #openstack-keystone | 11:20 | |
*** richm has quit IRC | 11:22 | |
*** thorst_afk has joined #openstack-keystone | 11:25 | |
*** Aqsa has joined #openstack-keystone | 11:30 | |
*** thorst_afk has quit IRC | 11:31 | |
*** markvoelker has joined #openstack-keystone | 11:36 | |
*** Aqsa has quit IRC | 11:39 | |
*** richm has joined #openstack-keystone | 11:40 | |
*** markvoelker has quit IRC | 11:40 | |
*** pcaruana has quit IRC | 11:53 | |
dstanek | bigjools: did you get if figured out? | 11:54 |
*** thorst_afk has joined #openstack-keystone | 11:55 | |
*** pcaruana has joined #openstack-keystone | 11:57 | |
*** links has quit IRC | 12:00 | |
*** zhurong has joined #openstack-keystone | 12:01 | |
*** catintheroof has joined #openstack-keystone | 12:30 | |
*** nicolasbock has quit IRC | 12:34 | |
*** markvoelker has joined #openstack-keystone | 12:37 | |
lbragstad | dstanek https://review.openstack.org/#/c/451941/9 in case you want to take another gander | 12:39 |
*** links has joined #openstack-keystone | 12:41 | |
*** markvoelker has quit IRC | 12:41 | |
*** ducttape_ has joined #openstack-keystone | 12:44 | |
*** nicolasbock has joined #openstack-keystone | 12:47 | |
*** felipemonteiro has joined #openstack-keystone | 12:49 | |
*** ducttape_ has quit IRC | 12:49 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Outline policy goals https://review.openstack.org/460344 | 12:52 |
lbragstad | edmondsw thanks for the review ^ | 12:52 |
lbragstad | attempted to address the comments in the latest patch (cc ayoung johnthetubaguy ) | 12:53 |
* johnthetubaguy nods (in a I must read that again way) | 12:53 | |
lbragstad | so far - the thing i like about that doc is that it's *under* 100 lines | 12:54 |
*** masber has quit IRC | 13:01 | |
*** gcb has joined #openstack-keystone | 13:01 | |
*** nicolasbock has quit IRC | 13:05 | |
*** felipemonteiro_ has joined #openstack-keystone | 13:08 | |
*** lamt has joined #openstack-keystone | 13:08 | |
*** felipemonteiro has quit IRC | 13:11 | |
*** felipemonteiro__ has joined #openstack-keystone | 13:13 | |
*** felipemonteiro_ has quit IRC | 13:13 | |
gcb | Keystone core reviewers: please help review patches https://review.openstack.org/#/q/status:open+project:openstack/keystone+branch:master+topic:bug/1686921 | 13:14 |
gcb | Most of them got +2 , need +A, they are fixing failures in requirements gate failure http://logs.openstack.org/18/461418/1/check/gate-cross-keystone-python27-ubuntu-xenial/8e652a1/testr_results.html.gz | 13:15 |
*** nicolasbock has joined #openstack-keystone | 13:22 | |
*** zhurong has quit IRC | 13:28 | |
*** chlong has quit IRC | 13:28 | |
*** lamt has quit IRC | 13:37 | |
*** gcb has quit IRC | 13:40 | |
*** gcb has joined #openstack-keystone | 13:40 | |
*** jaosorior is now known as jaosorior_away | 13:41 | |
openstackgerrit | ChangBo Guo(gcb) proposed openstack/keystone master: Fix keystone.tests.unit.test_v3_oauth1.MaliciousOAuth1Tests https://review.openstack.org/461279 | 13:42 |
*** gcb has quit IRC | 13:43 | |
*** gcb has joined #openstack-keystone | 13:44 | |
*** lucasxu has joined #openstack-keystone | 13:44 | |
*** ducttape_ has joined #openstack-keystone | 13:46 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add context to password_expires_days test https://review.openstack.org/461819 | 13:48 |
*** ducttape_ has quit IRC | 13:48 | |
*** ducttape_ has joined #openstack-keystone | 13:48 | |
*** felipemonteiro_ has joined #openstack-keystone | 13:53 | |
*** felipemonteiro__ has quit IRC | 13:57 | |
*** markvoelker has joined #openstack-keystone | 13:57 | |
*** links has quit IRC | 13:58 | |
*** ducttap__ has joined #openstack-keystone | 13:59 | |
gcb | lbragstad, I replied your comments in https://review.openstack.org/462001 , And thanks everyone for reviewing, It looks like we can merge all of them :-) | 13:59 |
lbragstad | gcb getting there :) | 14:00 |
lbragstad | gcb thanks for replying - +2/A | 14:01 |
*** lucasxu has quit IRC | 14:02 | |
*** zhurong has joined #openstack-keystone | 14:02 | |
lbragstad | gcb you don't have a patch up that closes bug 1686921 do you? | 14:02 |
openstack | bug 1686921 in OpenStack Identity (keystone) "There are wrong unit tests about config option usage" [Undecided,In progress] https://launchpad.net/bugs/1686921 - Assigned to Lance Bragstad (lbragstad) | 14:02 |
*** ducttape_ has quit IRC | 14:02 | |
*** lucasxu has joined #openstack-keystone | 14:03 | |
lbragstad | gcb from what i can tell most of those changes won't impact operators, will they? | 14:04 |
gcb | lbragstad, yes, only for the tests | 14:05 |
lbragstad | gcb ok - i was double checking to see if we needed a release note with the closes-bug patch | 14:05 |
gcb | also help developers to use right value for some config options | 14:06 |
gcb | lbragstad, I didn't have a patch to close the bug | 14:06 |
lbragstad | gcb i assume that will be the patch fixing the last failures? | 14:06 |
gcb | lbragstad, I checked all the failures and fixed them with Partial-Bug: #1686921, what about your patch , it seems all of mine got +A | 14:11 |
openstack | bug 1686921 in OpenStack Identity (keystone) "There are wrong unit tests about config option usage" [Undecided,In progress] https://launchpad.net/bugs/1686921 - Assigned to ChangBo Guo(gcb) (glongwave) | 14:11 |
*** lucasxu has quit IRC | 14:15 | |
gcb | lbragstad, the only pace may impact operator I found recently that maybe we can enhance the help string of config option in https://github.com/openstack/keystone/blob/master/keystone/conf/ldap.py#L193 | 14:15 |
gcb | s/pace/place | 14:15 |
gcb | https://review.openstack.org/#/c/462001/ 's commit message describe what kinds of string values for the config option 'user_enabled_default' | 14:16 |
lbragstad | gcb was that updated in any of your patches? | 14:16 |
lbragstad | ahhh | 14:16 |
lbragstad | we do a follow on for that | 14:17 |
gcb | maybe we can add similar description in the help text for the option | 14:17 |
*** lucasxu has joined #openstack-keystone | 14:17 | |
lbragstad | yeah | 14:17 |
*** openstackgerrit has quit IRC | 14:18 | |
*** lucasxu has quit IRC | 14:24 | |
*** lucasxu has joined #openstack-keystone | 14:24 | |
*** dave-mccowan has joined #openstack-keystone | 14:25 | |
*** lucasxu has quit IRC | 14:26 | |
knikolla | o/ | 14:29 |
knikolla | back from a few days of vacation | 14:29 |
*** lamt has joined #openstack-keystone | 14:40 | |
*** phalmos has joined #openstack-keystone | 14:48 | |
*** zhurong has quit IRC | 14:52 | |
*** phalmos_ has joined #openstack-keystone | 14:55 | |
lbragstad | o/ | 14:57 |
*** erlon has joined #openstack-keystone | 14:58 | |
*** phalmos has quit IRC | 14:58 | |
*** gcb has quit IRC | 15:02 | |
*** gcb has joined #openstack-keystone | 15:03 | |
*** voelzmo has quit IRC | 15:04 | |
*** gcb has quit IRC | 15:10 | |
*** phalmos has joined #openstack-keystone | 15:11 | |
*** phalmos_ has quit IRC | 15:11 | |
*** chlong has joined #openstack-keystone | 15:15 | |
knikolla | cmurphy: congrats! | 15:15 |
cmurphy | knikolla: ty! | 15:16 |
*** gcb has joined #openstack-keystone | 15:17 | |
knikolla | lbragstad: anything else i missed in the past days? | 15:29 |
lbragstad | knikolla just preparing for Boston | 15:29 |
lbragstad | :) | 15:29 |
lbragstad | knikolla people are counting on you to provide absolutely outstanding food recommendations | 15:29 |
lbragstad | knikolla no pressure | 15:30 |
knikolla | lbragstad: i'll happily oblige. i work a short walk from the convention center. | 15:30 |
knikolla | :) | 15:30 |
lbragstad | knikolla perfect! | 15:30 |
*** lamt has quit IRC | 15:33 | |
*** ducttape_ has joined #openstack-keystone | 15:34 | |
*** ducttap__ has quit IRC | 15:37 | |
*** lamt has joined #openstack-keystone | 15:40 | |
*** felipemonteiro_ has quit IRC | 15:43 | |
*** joe__w has joined #openstack-keystone | 15:45 | |
*** arunkant has quit IRC | 15:52 | |
*** ducttape_ has quit IRC | 15:53 | |
*** ducttape_ has joined #openstack-keystone | 15:53 | |
lbragstad | policy meeting starting in a few minutes | 15:58 |
lbragstad | cc johnthetubaguy edmondsw lamt gagehugo ^ | 15:59 |
edmondsw | lbragstad 10-4 | 15:59 |
lbragstad | hangout link https://hangouts.google.com/call/pofpk7oiynaqvn44rsli7t3uxqu | 16:00 |
*** openstackgerrit has joined #openstack-keystone | 16:06 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Outline policy goals https://review.openstack.org/460344 | 16:06 |
*** pcaruana has quit IRC | 16:24 | |
*** sjain has joined #openstack-keystone | 16:27 | |
*** tesseract has quit IRC | 16:38 | |
*** gyee has joined #openstack-keystone | 16:45 | |
*** esp has joined #openstack-keystone | 16:46 | |
*** mvk has quit IRC | 16:47 | |
*** harlowja has joined #openstack-keystone | 16:48 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Implement service_type alias lookups https://review.openstack.org/462218 | 16:54 |
mordred | efried: ^^ | 16:54 |
*** clenimar has quit IRC | 17:02 | |
openstackgerrit | Merged openstack/keystone master: Fix test keystone.tests.unit.test_token_bind.BindTest https://review.openstack.org/461275 | 17:03 |
openstackgerrit | Merged openstack/keystone master: Remove test_metadata_invalid_contact_type https://review.openstack.org/460873 | 17:04 |
openstackgerrit | Merged openstack/keystone master: Fix keystone.tests.unit.test_backend_ldap.LDAPIdentity https://review.openstack.org/461273 | 17:04 |
openstackgerrit | Merged openstack/keystone master: override config option notification_opt_out with list https://review.openstack.org/461271 | 17:04 |
openstackgerrit | Merged openstack/keystone master: Fix test_minimum_password_age_and_password_expires_days_deactivated https://review.openstack.org/460879 | 17:04 |
ayoung | edmondsw, were you going to submit a version of https://review.openstack.org/#/c/257636/ To your liking? I think I've gone as far as I can without making some more fundamental changes, based on those last test failures | 17:06 |
edmondsw | ayoung I tried, but it's unworkable... commented to that effect | 17:06 |
ayoung | edmondsw, hmmm | 17:07 |
edmondsw | ayoung you should read my comments :) | 17:08 |
ayoung | edmondsw, what do you think of getting something in prior to that patch that does the scope check? | 17:08 |
edmondsw | ayoung what do you mean? | 17:08 |
ayoung | edmondsw, for example, your comment: E.g. get_user checks RULE_ADMIN_OR_OWNER, which doesn't check is_admin_project, so any admin can get_user for any user | 17:09 |
ayoung | we really need to nail down the scope checks in order to get this right | 17:09 |
edmondsw | my approach here would be to tackle one resource at a time | 17:09 |
*** sjain has quit IRC | 17:09 | |
edmondsw | add scope checks for users in one patch, for groups in another, for projects in a 3rd, etc. | 17:10 |
edmondsw | in the code | 17:10 |
ayoung | edmondsw, right...users and groups should be either global admin OR domain admin | 17:10 |
ayoung | edmondsw, I can dig that | 17:10 |
ayoung | projects are going to be the most convoluted. We might find we *have* to do that in code | 17:10 |
edmondsw | we should *want* to do that in code anyway :) | 17:11 |
edmondsw | we just had a good conversation in the policy meeting about this | 17:11 |
edmondsw | lbragstad ^ | 17:11 |
*** lucasxu has joined #openstack-keystone | 17:12 | |
ayoung | edmondsw, sorry I missed it. Internal meeting. | 17:13 |
ayoung | edmondsw, OK, I'll redo this patch as is_admin_project only checks for non-scoped operations like endpoints and services | 17:14 |
ayoung | I'll remove checks on users, groups, projects, role assignements | 17:14 |
edmondsw | +! | 17:14 |
ayoung | cool. I think that is a sensible approach | 17:15 |
ayoung | and...lunch is rady! | 17:15 |
*** ducttap__ has joined #openstack-keystone | 17:16 | |
*** ducttape_ has quit IRC | 17:16 | |
edmondsw | lbragstad I missed one thing on https://review.openstack.org/#/c/460344 but should be an easy fix | 17:17 |
*** nicodemus_ has joined #openstack-keystone | 17:18 | |
*** ducttap__ has quit IRC | 17:32 | |
*** thorst_afk is now known as thorst | 17:34 | |
lbragstad | edmondsw sweet | 17:35 |
lbragstad | edmondsw ayoung i just got off a call | 17:35 |
ayoung | lbragstad, take a quick read up, and you can see the next steps: | 17:35 |
lbragstad | edmondsw ayoung i'm going to update the goals doc and then start trying to capture the conversation we had with lamt and gagehugo | 17:35 |
ayoung | 1. rewrite https://review.openstack.org/#/c/257636/ so it does not attempt to sort anything for scoped calls | 17:36 |
ayoung | 2. we'll start working on specific patches for scoped calls like create users etc | 17:36 |
*** aojea has quit IRC | 17:36 | |
*** ducttape_ has joined #openstack-keystone | 17:45 | |
*** mtreinish has quit IRC | 17:46 | |
*** ducttap__ has joined #openstack-keystone | 17:47 | |
*** ducttape_ has quit IRC | 17:50 | |
ayoung | edmondsw, lbragstad for the first hack on the policy, I am only going to lock down the operations that affect state change: create, update, delete of endpoints, services, and a couple others | 17:53 |
*** mvk has joined #openstack-keystone | 18:04 | |
*** ducttap__ has quit IRC | 18:05 | |
*** mtreinish has joined #openstack-keystone | 18:05 | |
*** lucasxu has quit IRC | 18:11 | |
*** lucasxu has joined #openstack-keystone | 18:11 | |
*** ducttape_ has joined #openstack-keystone | 18:23 | |
*** voelzmo has joined #openstack-keystone | 18:23 | |
*** david-lyle has quit IRC | 18:24 | |
*** dklyle has joined #openstack-keystone | 18:24 | |
edmondsw | ayoung please make the changes in the API code rather than in policy code | 18:30 |
openstackgerrit | Merged openstack/keystone master: Fix keystone.tests.unit.test_v3_oauth1.MaliciousOAuth1Tests https://review.openstack.org/461279 | 18:31 |
lbragstad | edmondsw ++ yeah - that logic should live with the resource's code since it's an opinion of that resource | 18:43 |
-openstackstatus- NOTICE: Gerrit on review.openstack.org is being restarted to accomodate a memory leak in Gerrit. Service should return shortly. | 18:52 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Outline policy goals https://review.openstack.org/460344 | 18:55 |
*** masterjcool has quit IRC | 18:58 | |
*** masterjcool has joined #openstack-keystone | 19:10 | |
*** ducttape_ has quit IRC | 19:37 | |
*** markvoelker has quit IRC | 19:51 | |
*** gyee has quit IRC | 19:55 | |
*** markvoelker has joined #openstack-keystone | 19:58 | |
*** voelzmo has quit IRC | 20:00 | |
*** voelzmo has joined #openstack-keystone | 20:00 | |
*** ducttape_ has joined #openstack-keystone | 20:10 | |
*** voelzmo has quit IRC | 20:13 | |
*** catinthe_ has joined #openstack-keystone | 20:21 | |
*** ducttap__ has joined #openstack-keystone | 20:22 | |
*** catintheroof has quit IRC | 20:24 | |
*** ducttape_ has quit IRC | 20:26 | |
*** lucasxu has quit IRC | 20:28 | |
*** ducttape_ has joined #openstack-keystone | 20:30 | |
*** ducttap__ has quit IRC | 20:33 | |
*** raildo has quit IRC | 20:34 | |
*** dave-mccowan has quit IRC | 20:41 | |
*** catinthe_ has quit IRC | 20:45 | |
edmondsw | ayoung you should check the comments on https://bugs.launchpad.net/keystone/+bug/968696 | 20:46 |
openstack | Launchpad bug 968696 in OpenStack Identity (keystone) ""admin"-ness not properly scoped" [High,In progress] - Assigned to Adam Young (ayoung) | 20:46 |
samueldmq | how does an administrative password reset happens in keystone? | 20:48 |
samueldmq | I only see an option to a user update his own password | 20:48 |
rodrigods | samueldmq, via the usual user update route | 20:49 |
samueldmq | rodrigods: thanks | 20:50 |
*** jose-phillips has joined #openstack-keystone | 21:03 | |
*** jose-phi_ has quit IRC | 21:05 | |
*** jose-phillips has quit IRC | 21:05 | |
*** jose-phillips has joined #openstack-keystone | 21:06 | |
openstackgerrit | Emile Snyder proposed openstack/keystonemiddleware master: Add a test for auth_token revocation list caching behavior. https://review.openstack.org/462291 | 21:08 |
*** thorst has quit IRC | 21:13 | |
*** chlong has quit IRC | 21:17 | |
*** jsavak has joined #openstack-keystone | 21:18 | |
*** gyee has joined #openstack-keystone | 21:25 | |
*** nicodemus_ has quit IRC | 21:28 | |
samueldmq | lbragstad: bug 1688119 | 21:36 |
openstack | bug 1688119 in OpenStack Identity (keystone) "change_password_after_first_use is not honored" [Undecided,New] https://launchpad.net/bugs/1688119 | 21:36 |
samueldmq | lbragstad: bug 1688119 | 21:36 |
samueldmq | would be nice if someone could confirm that ^ | 21:37 |
*** thorst has joined #openstack-keystone | 21:38 | |
*** thorst has quit IRC | 21:43 | |
samueldmq | and bug 1688123 | 21:48 |
openstack | bug 1688123 in OpenStack Identity (keystone) "ignore_password_expiry is not honored" [Undecided,New] https://launchpad.net/bugs/1688123 | 21:48 |
*** ducttap__ has joined #openstack-keystone | 21:48 | |
*** ducttape_ has quit IRC | 21:48 | |
lbragstad | samueldmq thanks for the heads up | 21:49 |
lbragstad | samueldmq i can look into it | 21:49 |
*** jsavak has quit IRC | 21:49 | |
samueldmq | lbragstad: perfect, it'd be nice if you could confirm/see if I am missing something | 21:50 |
samueldmq | there will be a live demo next week in my talk at the summit :-) | 21:50 |
*** brad[] has quit IRC | 21:52 | |
*** jose-phillips has quit IRC | 21:54 | |
*** jose-phillips has joined #openstack-keystone | 22:00 | |
*** brad[] has joined #openstack-keystone | 22:05 | |
*** cmurphy_ has joined #openstack-keystone | 22:23 | |
*** ediardo_ has joined #openstack-keystone | 22:23 | |
*** cmurphy has quit IRC | 22:26 | |
*** cmurphy_ is now known as cmurphy | 22:26 | |
*** htruta` has joined #openstack-keystone | 22:27 | |
*** rodrigod` has joined #openstack-keystone | 22:27 | |
*** erlon has quit IRC | 22:28 | |
*** ediardo has quit IRC | 22:28 | |
*** rodrigods has quit IRC | 22:28 | |
*** harlowja has quit IRC | 22:28 | |
*** d0ugal has quit IRC | 22:28 | |
*** ediardo_ is now known as ediardo | 22:29 | |
*** jose-phillips has quit IRC | 22:36 | |
*** aloga has quit IRC | 22:50 | |
*** aloga has joined #openstack-keystone | 22:51 | |
*** d0ugal has joined #openstack-keystone | 22:53 | |
*** lamt has quit IRC | 23:02 | |
*** lamt has joined #openstack-keystone | 23:02 | |
*** lamt has quit IRC | 23:05 | |
*** lamt has joined #openstack-keystone | 23:07 | |
*** lamt has quit IRC | 23:07 | |
*** ducttap__ has quit IRC | 23:10 | |
*** ducttape_ has joined #openstack-keystone | 23:13 | |
*** dklyle has quit IRC | 23:23 | |
*** phalmos has quit IRC | 23:26 | |
*** harlowja has joined #openstack-keystone | 23:31 | |
*** ducttape_ has quit IRC | 23:32 | |
*** lamt has joined #openstack-keystone | 23:35 | |
*** gcb has quit IRC | 23:42 | |
*** ducttape_ has joined #openstack-keystone | 23:53 | |
*** lamt has quit IRC | 23:54 | |
*** lamt has joined #openstack-keystone | 23:54 | |
*** ducttape_ has quit IRC | 23:57 | |
*** thorst has joined #openstack-keystone | 23:58 | |
*** thorst has quit IRC | 23:58 | |
*** masber has joined #openstack-keystone | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!