Comment 24 for bug 1331912

Revision history for this message
Brant Knudson (blk-u) wrote : Re: V2 Trusts allow trustee to emulate trustor in other projects (CVE-2014-3520)

Looking at the commit message, it doesn't make sense:

Previously if a trustee requests a trust scoped token for a project that
is different to the one in the trust, however the trustor has the
appropriate roles then a token would be issued.

I think "however" is meant to be "if"