Comment 13 for bug 1872733

Revision history for this message
Gage Hugo (gagehugo) wrote : Re: Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID

I believe I was thinking that an authenticated user would be able to guess easier than a remote non-authenticated user. I'm fine with classifying this as C1 since it really does depend on UUID guessing.