The system grant policies were not taking the default roles work we
did last release into account. This commit changes the default
policies to rely on the ``reader`` role for getting and listing system
assignments. Subsequent patches will incorporate:
- system member test coverage
- system admin functionality
- domain user test coverage
- project user test coverage
Reviewed: https:/ /review. openstack. org/647673 /git.openstack. org/cgit/ openstack/ keystone/ commit/ ?id=fd08266abb3 a4fb18ac05921ca 11c4768daa2f6d
Committed: https:/
Submitter: Zuul
Branch: stable/stein
commit fd08266abb3a4fb 18ac05921ca11c4 768daa2f6d
Author: Lance Bragstad <email address hidden>
Date: Tue Dec 4 22:24:40 2018 +0000
Update system grant policies for system reader
The system grant policies were not taking the default roles work we
did last release into account. This commit changes the default
policies to rely on the ``reader`` role for getting and listing system
assignments. Subsequent patches will incorporate:
- system member test coverage
- system admin functionality
- domain user test coverage
- project user test coverage
Change-Id: I838c85f315864d 2f0baf747d6bcc5 46724e4673a 9253a52d7e45706 7cf63d3ba8)
Related-Bug: 1805368
Related-Bug: 1750669
Related-Bug: 1806762
(cherry picked from commit 465a8bb59be1373