Update system group assignment policies for reader and member
This commit introduces the reader and member default roles to the
system assignment API for groups. Users with the `reader` and `member`
role on the system should be able to list and check system role
assignments for all users in the deployment.
Subsequent patches will:
- simplify the policies for system admin
- add domain user test coverage
- add project user test coverage
- remove obsolete policies from policy.v3cloudsample.json
Reviewed: https:/ /review. openstack. org/647678 /git.openstack. org/cgit/ openstack/ keystone/ commit/ ?id=1d8ac830a1e d6a571db6987d4e f657cf3e04d640
Committed: https:/
Submitter: Zuul
Branch: stable/stein
commit 1d8ac830a1ed6a5 71db6987d4ef657 cf3e04d640
Author: Lance Bragstad <email address hidden>
Date: Thu Mar 21 18:21:42 2019 +0000
Update system group assignment policies for reader and member
This commit introduces the reader and member default roles to the
system assignment API for groups. Users with the `reader` and `member`
role on the system should be able to list and check system role
assignments for all users in the deployment.
Subsequent patches will:
- simplify the policies for system admin v3cloudsample. json
- add domain user test coverage
- add project user test coverage
- remove obsolete policies from policy.
Change-Id: I7eebb1b07213a1 406e98f8a621ec4 4c87b812457 e6b54c5453a05c4 0a73abee85)
Related-Bug: 1805368
Related-Bug: 1750669
Related-Bug: 1806762
(cherry picked from commit 593e67e6ca429c6