Activity log for bug #1808859

Date Who What changed Old value New value Message
2018-12-17 19:32:05 Lance Bragstad bug added bug
2018-12-17 19:32:17 Lance Bragstad tags policy
2018-12-17 19:32:25 Lance Bragstad tags policy policy system-scope
2018-12-17 19:34:26 Lance Bragstad description Keystone implemented scope_types for oslo.policy RuleDefault objects in the Queens release [0]. In order to take full advantage of scope_types, keystone is going to have to evolve policy enforcement checks in the group API. This is documented in each patch with FIXMEs [1]. System users should be able to manage groups across all domains in the deployment. Domain users should be able to manage groups within the domain they have authorization on. Project users shouldn't be able to manage groups at all, since group entities are domain-specific. [0] https://review.openstack.org/#/c/525706/ [1] https://review.openstack.org/#/c/525706/3/keystone/common/policies/group.py Keystone implemented scope_types for oslo.policy RuleDefault objects in the Queens release [0]. In order to take full advantage of scope_types, keystone is going to have to evolve policy enforcement checks in the group API. This is documented in each patch with FIXMEs [1]. System users should be able to manage groups across all domains in the deployment. Domain users should be able to manage groups within the domain they have authorization on. Project users shouldn't be able to manage groups at all, since group entities are domain-specific. [0] https://review.openstack.org/#/c/525706/ [1] https://git.openstack.org/cgit/openstack/keystone/tree/keystone/common/policies/group.py?id=20f11eb88a7d8bf534fa221ebeae4ae9c87cdc0b#n21
2018-12-17 19:35:00 Lance Bragstad keystone: status New Triaged
2018-12-17 19:35:02 Lance Bragstad keystone: importance Undecided High
2019-03-12 14:36:53 Colleen Murphy keystone: milestone stein-rc1
2019-03-18 13:23:41 OpenStack Infra keystone: status Triaged In Progress
2019-03-18 13:23:41 OpenStack Infra keystone: assignee Colleen Murphy (krinkle)
2019-03-20 21:38:06 Colleen Murphy keystone: milestone stein-rc1 stein-rc2
2019-04-01 05:41:25 OpenStack Infra keystone: status In Progress Fix Released
2019-04-02 11:04:35 OpenStack Infra tags policy system-scope in-stable-stein policy system-scope