I would adjust the description in comment #30 by removing the term "federated":
"By doing GET /v3/OS-FEDERATION/projects with a federated token
an actor may discover projects they have no authority to access,
leaking all projects in the deployment and their attributes."
to
"Calling GET /v3/OS-FEDERATION/projects an actor may discover
projects they have no authority to access, leaking all projects
in the deployment and their attributes."
I would adjust the description in comment #30 by removing the term "federated":
"By doing GET /v3/OS- FEDERATION/ projects with a federated token
an actor may discover projects they have no authority to access,
leaking all projects in the deployment and their attributes."
to
"Calling GET /v3/OS- FEDERATION/ projects an actor may discover
projects they have no authority to access, leaking all projects
in the deployment and their attributes."