Assignment API confirms user in Identity API

Bug #1211388 reported by Adam Young on 2013-08-12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Adam Young

Bug Description

In get_roles_for_user_and_domain and get_roles_for_user_and_project, the assignment API calls into the Identity API to confirm that the user exists. This call is makes it impossible to implement external authentication where the user is queried solely based on their current credential. Also, this call is not required, as the user liveness will and should be checked earlier in the token creation process.

If it is important for a certain API call to check if a user uis active, it should be part of the controler call and not part of the core function.

These calls are expensive; the make an additional RPC to the Database or Directory store.

Fix proposed to branch: master

Changed in keystone:
status: New → In Progress

Submitter: Jenkins
Branch: master

commit 3be931165c6e218aaa5355a1f435ae58eb4484eb
Author: Adam Young <email address hidden>
Date: Mon Aug 12 12:51:59 2013 -0400

    Remove User Check from Assignments

    Removed tests that assume too tight a coupling between identity
    and assignment backends.

    Bug 1211388

    Change-Id: I45e05273282e3c8cc79f48891e436d7694825f9e

Changed in keystone:
status: In Progress → Fix Committed
Thierry Carrez (ttx) on 2013-09-05
Changed in keystone:
milestone: none → havana-3
status: Fix Committed → Fix Released
Dolph Mathews (dolph) on 2013-09-19
Changed in keystone:
importance: Undecided → Medium
Thierry Carrez (ttx) on 2013-10-17
Changed in keystone:
milestone: havana-3 → 2013.2
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers