The token data for a trust-scoped token can contain duplicate roles

Bug #1778109 reported by Jeremy Freudberg
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
Undecided
Jeremy Freudberg

Bug Description

When dealing with implied roles, the token data for a trust-scoped token might contain duplicate roles.

(This can break the interaction between, for example, Sahara and Heat.)

Changed in keystone:
assignee: nobody → Jeremy Freudberg (jfreud)
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Related fix merged to keystone (master)

Reviewed: https://review.openstack.org/576610
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=89a5783dd887288981434d7efd3ddd7ce93d4f40
Submitter: Zuul
Branch: master

commit 89a5783dd887288981434d7efd3ddd7ce93d4f40
Author: Jeremy Freudberg <email address hidden>
Date: Tue Jun 19 18:36:59 2018 +0000

    Expose duplicate role names bug in trusts

    Related-Bug: #1778109

    Change-Id: Iff61a0a81566b576ec875b1fb42cb8ede538470f

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/576611
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=50fd6933e8ab5ccf4ef232837fbe582d90c5c913
Submitter: Zuul
Branch: master

commit 50fd6933e8ab5ccf4ef232837fbe582d90c5c913
Author: Jeremy Freudberg <email address hidden>
Date: Tue Jun 19 18:54:36 2018 +0000

    Fix duplicate role names in trusts bug

    Closes-Bug: #1778109

    Change-Id: Id0953190b3b1e0b6765430fbb10d16e7f53f53ee

Changed in keystone:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/keystone 14.0.0.0rc1

This issue was fixed in the openstack/keystone 14.0.0.0rc1 release candidate.

Changed in keystone:
milestone: none → rocky-3
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.