Tuesday, 2026-03-10

opendevreviewBoris Bobrov proposed openstack/keystone master: Add FederatedSystemScopedPayload for federated system-scoped tokens  https://review.opendev.org/c/openstack/keystone/+/97978907:31
opendevreviewBoris Bobrov proposed openstack/keystone master: Add FederatedSystemScopedPayload for federated system-scoped tokens  https://review.opendev.org/c/openstack/keystone/+/97978909:40
bbobrovcardoe: ^10:38
opendevreviewMerged openstack/keystone master: Keystone identity mapping to support project definition as a JSON  https://review.opendev.org/c/openstack/keystone/+/74223510:44
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Readd the protection test tox based job  https://review.opendev.org/c/openstack/keystone/+/88643412:11
cardoebbobrov: awesome. My only comment would be to change the bottom elif to else that way the whole function is covered to always return what its documented to return15:32
cardoeCan we backport that as well?15:32
bbobrovcardoe: if it would return regardless of what it found, we would have a much harder time debugging the issue.15:42
bbobrovwhat we should do is add "else:" and then raise assertion error with text "this is a programming error, report this as a bug"15:43
cardoeThat'd be good with me else and raise16:22
lajoskatonaHi Keystone team! I opened a bug for LDAP pw expiration, see : https://bugs.launchpad.net/keystone/+bug/213872516:27
lajoskatonaI pushed a wip patch also for it few weeks back: https://review.opendev.org/c/openstack/keystone/+/97661816:27
lajoskatonamy basic aproach was to add cfg option for the user to add select from some predefined methods which can be used for his/her ldap backend to convert the returned pw expiration value to something that Keystone can understand16:29
lajoskatonaPlease check if this direction is something to work on or there should be some better way to handle different ldap backends tricks for pw expiration16:30
opendevreviewMerged openstack/keystoneauth master: Run mypy from tox  https://review.opendev.org/c/openstack/keystoneauth/+/97046116:53
bbobrovlajoskatona: if you would like to get a feedback on the direction, you should start with a spec in keystone-specs repo. There you need to describe what you want to implement and why, and what alternatives you considered.17:56
lajoskatonabbobrov: ack, so a spec is needed it is not enough to handle as a bug ? that is already a help 18:02
bbobrovlajoskatona: i would say yes. I am not a core reviewer though.18:07
bbobrovlajoskatona: i have left some comments on gerrit18:07
lajoskatonabbobrov: thanks, I will check it18:19
opendevreviewHarry Kominos proposed openstack/keystone master: [doc] Amend IDP list-idp example  https://review.opendev.org/c/openstack/keystone/+/97991020:48

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!