keystone v2 allows creation of is_domain=True projects

Bug #1496946 reported by Henrique Truta
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
High
Henrique Truta

Bug Description

in keystone v2 controller layer, there is no check if the project has the is_domain field set True:
https://github.com/openstack/keystone/blob/master/keystone/resource/controllers.py#L95

keystone v2 must not allow the creation of such projects

Changed in keystone:
assignee: nobody → Henrique Truta (henriquetruta)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/224876

Changed in keystone:
status: New → In Progress
Revision history for this message
Dolph Mathews (dolph) wrote :

Is this a problem in previous releases?

Changed in keystone:
importance: Undecided → Medium
importance: Medium → High
tags: added: kilo-backport-potential
Dolph Mathews (dolph)
tags: added: hierarchical-multitenancy
Changed in keystone:
assignee: Henrique Truta (henriquetruta) → David Stanek (dstanek)
David Stanek (dstanek)
Changed in keystone:
assignee: David Stanek (dstanek) → Henrique Truta (henriquetruta)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/224876
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=5599226956fa788114747d6784e0bf7151c84d05
Submitter: Jenkins
Branch: master

commit 5599226956fa788114747d6784e0bf7151c84d05
Author: henriquetruta <email address hidden>
Date: Thu Sep 17 14:45:44 2015 -0300

    Prevents creating is_domain=True projects in v2

    Keystone v2 must not allow the creation of projects with the is_domain
    field set True.

    Co-Authored-By: Rodrigo Duarte <email address hidden>

    Change-Id: I569e4ab147a16bb019fb3d5f4f6218c75f4a3cca
    Closes-Bug: 1496946

Changed in keystone:
status: In Progress → Fix Released
Changed in keystone:
milestone: none → mitaka-3
Revision history for this message
Thierry Carrez (ttx) wrote : Fix included in openstack/keystone 9.0.0.0b3

This issue was fixed in the openstack/keystone 9.0.0.0b3 development milestone.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.