Thursday, 2026-05-14

sean-k-mooneysecond time lucky.14:30
sean-k-mooneyhi folks i was looking at the keystone issue tracker before fileing a bug and i came across a public issue that likely shoudl have been private so i was wodnerign if we should at least mark it as public-secuirty14:31
sean-k-mooneyit requires an admin to configure a feautre that is not enabeld by default14:31
sean-k-mooneybut the report assert a path to gain roles in other porjects14:31
sean-k-mooneyhttps://bugs.launchpad.net/keystone/+bug/214859914:31
sean-k-mooneythat has been public for a month at this point so we are proably well past the point where we coudl make it private14:32
sean-k-mooneywith that said the feature that its refesince was added 2 months ago14:32
sean-k-mooneyso i think this is not in a release yet14:32
sean-k-mooneyperhaps milestoen 1 14:32
sean-k-mooneyhum no its in 2026.1 https://review.opendev.org/c/openstack/keystone/+/74223514:33
JayFgouthamr: fungi: rosmaita: ^14:40
JayFtl;dr looks like a class A was filed as a public bug, at least on the surface14:40
fungithanks sean-k-mooney, JayF! i've switched it to public security type and added an incomplete security advisory bugtask14:55
sean-k-mooneyi have flagged it in tnerally to one of the keystoen core sec member as well and they are goign to reivew it again14:56
fungihttps://bugs.launchpad.net/keystone/+bug/2148825 is now public15:03

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!