Comment 23 for bug 1331912

Revision history for this message
Brant Knudson (blk-u) wrote : Re: V2 Trusts allow trustee to emulate trustor in other projects (CVE-2014-3520)

0001-Ensure-that-in-v2-auth-tenant_id-matches-trust.patch -- comment 4 (master)
 - tests: passed
 - manual inspection: +1

icehouse -- comment 15 (icehouse)
 - tests: passed
 - manual inspection: +1

havana.patch -- comment 9 (havana)
 - tests:
 - manual inspection: +1

impact statement -- comment 12
 - the text "required roles in the requested project id" should have "id" removed.
 - the text "trusts and V2 API" should be "trusts and the Identity V2 API"
   (in case someone things there's a trust v2 api or something)