No notifications for role grants using v2
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
Fix Released
|
Medium
|
Brant Knudson | ||
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
If you use the v3 API to add or remove role grants, you get notifications that it happened, but if you use the v2.0 API, you don't get notifications.
Keystone needs to send notifications when the v2 API is used, also.
For example, start with devstack, then grant a role:
$ keystone user-role-add --user demo --tenant admin --role admin
- gets a notification for identity.
Same for revoke:
$ keystone user-role-remove --user demo --tenant admin --role admin
- gets a notification for identity.
v3 works fine:
$ curl -X PUT -H "X-Auth-Token: $TOKEN" http://
$ curl -X DELETE -H "X-Auth-Token: $TOKEN" http://
Changed in keystone: | |
assignee: | nobody → Brant Knudson (blk-u) |
Changed in keystone: | |
importance: | Undecided → Medium |
tags: | added: kilo-rc-potential |
Changed in keystone: | |
milestone: | none → kilo-rc1 |
Changed in keystone: | |
status: | Fix Committed → Fix Released |
Changed in keystone: | |
milestone: | kilo-rc1 → 2015.1.0 |
Fix proposed to branch: master /review. openstack. org/166934
Review: https:/