Friday, 2020-06-12

openstackgerritBo Tran proposed openstack/keystone master: fix error when using token was created from application credentials
gshippeyHi all, I was reading and Question number 2 piqued my interest. Q: Will users of different domains be allowed within the same group? A: Groups, as defined here, are bound to a domain. Only users of that domain can be a members of the groups defined in that domain09:33
gshippeyAm i right in saying that the answer is no longer true? When playing around with federation I have been assigning users from an IDP with a randomly generated domain to groups/projects in the default domain with no issues so far.09:34
vishakhagshippey: A is true and it is the current scenario.10:25
vishakhagshippey: Could you list the groups/projects  under default domain and confirm whether they exists in it or not?10:26
gshippey    <-- an example where I add a shadow user who has logged in through my idp assigned to a randomly generated domain to a group that exists within the default domain.10:42
vishakhagshippey: I can see that user of different domain is being added to a group existing in another domain. Could you register this scenario in a bug. So that I can discuss this scenario with team and update on the same.11:14
gshippeyI will do so. Thanks for your clarification.11:15
vishakhagshippey:  Thanks11:16
