Mapping a federated user to a local user does not return concrete role assignments

Bug #1667070 reported by Ron De Rose
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Triaged
Medium
Unassigned

Bug Description

When mapping a federated user to a local user, only federated projects and roles are returned; not the local user's concrete role assignments and projects.

Will update this with a mapping example and steps to reproduce.

Tags: federation
Changed in keystone:
assignee: nobody → Ron De Rose (ronald-de-rose)
tags: added: federation
Revision history for this message
Henry Nash (henry-nash) wrote :

What happens if the mapping also contains group membership (and hence roles) based on your federation assertions? Do you get the superset of all the roles? Only the local ones? Is this an error situation?

Revision history for this message
Ron De Rose (ronald-de-rose) wrote :

If you have a group mapping then you would get a combined set of roles (concrete and group membership).

Changed in keystone:
importance: Undecided → Medium
status: New → Triaged
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/451604

Changed in keystone:
status: Triaged → In Progress
Revision history for this message
Lance Bragstad (lbragstad) wrote :

Automatically unassigning due to inactivity.

Changed in keystone:
assignee: Ron De Rose (ronald-de-rose) → nobody
status: In Progress → Triaged
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on keystone (master)

Change abandoned by "Gage Hugo <email address hidden>" on branch: master
Review: https://review.opendev.org/c/openstack/keystone/+/451604
Reason: Abandoning since there hasn't been any recent activity, if anyone wants to continue this work, please feel free to restore this or create a new change.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.