mordred | yeah ... we're going to have some fun aren't we? | 00:06 |
---|---|---|
*** rcernin has joined #openstack-keystone | 00:08 | |
*** whoami-rajat has joined #openstack-keystone | 00:09 | |
*** markvoelker has joined #openstack-keystone | 00:10 | |
*** markvoelker has quit IRC | 00:16 | |
*** dancn has quit IRC | 00:20 | |
*** markvoelker has joined #openstack-keystone | 00:21 | |
*** trident has quit IRC | 00:38 | |
*** gyee has quit IRC | 00:48 | |
*** rcernin has quit IRC | 00:58 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone-specs master: Reparent Projects https://review.opendev.org/618144 | 01:02 |
openstackgerrit | Adrian Turjak proposed openstack/keystone-specs master: Reparent Projects https://review.opendev.org/618144 | 01:03 |
*** spsurya has joined #openstack-keystone | 01:05 | |
*** rcernin has joined #openstack-keystone | 01:14 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: Add support for previous TOTP windows https://review.opendev.org/647655 | 01:17 |
*** markvoelker has quit IRC | 01:23 | |
*** markvoelker has joined #openstack-keystone | 01:23 | |
*** markvoelker has quit IRC | 01:28 | |
*** markvoelker has joined #openstack-keystone | 01:56 | |
*** markvoelker has quit IRC | 02:00 | |
*** whoami-rajat has quit IRC | 02:28 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader and member for endpoint_groups https://review.opendev.org/675272 | 03:12 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system_admin for endpoint_groups https://review.opendev.org/675536 | 03:13 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for domain users interacting with endpoint_groups https://review.opendev.org/676108 | 03:13 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for project users interacting with endpoint_groups https://review.opendev.org/676115 | 03:14 |
*** whoami-rajat has joined #openstack-keystone | 03:20 | |
*** markvoelker has joined #openstack-keystone | 04:01 | |
*** markvoelker has quit IRC | 04:05 | |
*** markvoelker has joined #openstack-keystone | 04:52 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader and member for policies https://review.opendev.org/676162 | 04:54 |
*** markvoelker has quit IRC | 04:57 | |
*** rcernin has quit IRC | 06:16 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system admin for policies https://review.opendev.org/676355 | 06:18 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader and member for policies https://review.opendev.org/676162 | 06:23 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system admin for policies https://review.opendev.org/676355 | 06:24 |
*** rcernin has joined #openstack-keystone | 06:31 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader and member for endpoint_groups https://review.opendev.org/675272 | 06:42 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system_admin for endpoint_groups https://review.opendev.org/675536 | 06:42 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system_admin for endpoint_groups https://review.opendev.org/675536 | 06:53 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for domain users interacting with endpoint_groups https://review.opendev.org/676108 | 06:54 |
*** ivve has joined #openstack-keystone | 06:59 | |
*** trident has joined #openstack-keystone | 07:01 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for domain users interacting with endpoint_groups https://review.opendev.org/676108 | 07:01 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add tests for project users interacting with endpoint_groups https://review.opendev.org/676115 | 07:02 |
*** xek has joined #openstack-keystone | 07:03 | |
*** tesseract has joined #openstack-keystone | 07:10 | |
*** shyamb has joined #openstack-keystone | 07:16 | |
*** dancn has joined #openstack-keystone | 07:16 | |
*** shyamb has quit IRC | 07:41 | |
*** dancn has quit IRC | 07:50 | |
*** shyamb has joined #openstack-keystone | 07:53 | |
*** rcernin has quit IRC | 07:56 | |
*** dancn has joined #openstack-keystone | 08:03 | |
*** markvoelker has joined #openstack-keystone | 08:07 | |
*** tkajinam has quit IRC | 08:11 | |
*** markvoelker has quit IRC | 08:15 | |
*** rcernin has joined #openstack-keystone | 08:23 | |
*** rcernin has quit IRC | 08:29 | |
*** rcernin has joined #openstack-keystone | 08:38 | |
*** markvoelker has joined #openstack-keystone | 08:41 | |
*** markvoelker has quit IRC | 08:45 | |
*** shyamb has quit IRC | 08:52 | |
*** rcernin has quit IRC | 09:04 | |
*** markvoelker has joined #openstack-keystone | 09:10 | |
*** markvoelker has quit IRC | 09:15 | |
*** dancn has quit IRC | 09:15 | |
*** dancn has joined #openstack-keystone | 09:20 | |
*** shyamb has joined #openstack-keystone | 09:52 | |
*** markvoelker has joined #openstack-keystone | 10:11 | |
*** markvoelker has quit IRC | 10:15 | |
*** bnemec has quit IRC | 10:34 | |
*** shyamb has quit IRC | 10:35 | |
*** bnemec has joined #openstack-keystone | 10:37 | |
*** shyamb has joined #openstack-keystone | 10:42 | |
*** bnemec has quit IRC | 10:45 | |
*** bnemec has joined #openstack-keystone | 10:49 | |
*** bnemec has quit IRC | 11:04 | |
*** bnemec has joined #openstack-keystone | 11:09 | |
*** bnemec has quit IRC | 11:13 | |
*** markvoelker has joined #openstack-keystone | 11:21 | |
*** markvoelker has quit IRC | 11:26 | |
*** bnemec has joined #openstack-keystone | 11:26 | |
*** markvoelker has joined #openstack-keystone | 11:31 | |
*** bnemec has quit IRC | 11:31 | |
*** raildo has joined #openstack-keystone | 11:35 | |
*** markvoelker has quit IRC | 11:36 | |
*** jaosorior has joined #openstack-keystone | 11:38 | |
*** bnemec has joined #openstack-keystone | 11:38 | |
*** bnemec has quit IRC | 11:45 | |
*** shyamb has quit IRC | 11:45 | |
*** bnemec has joined #openstack-keystone | 11:48 | |
*** bnemec has quit IRC | 11:55 | |
*** bnemec has joined #openstack-keystone | 11:59 | |
*** shyamb has joined #openstack-keystone | 12:02 | |
*** markvoelker has joined #openstack-keystone | 12:02 | |
*** bnemec has quit IRC | 12:04 | |
*** bnemec has joined #openstack-keystone | 12:10 | |
*** bnemec has quit IRC | 12:29 | |
*** bnemec has joined #openstack-keystone | 12:33 | |
*** rcernin has joined #openstack-keystone | 12:34 | |
*** shyamb has quit IRC | 12:36 | |
*** rcernin has quit IRC | 12:40 | |
*** bnemec has quit IRC | 12:41 | |
*** bnemec has joined #openstack-keystone | 12:44 | |
*** bnemec has quit IRC | 12:49 | |
*** bnemec has joined #openstack-keystone | 12:54 | |
*** jaosorior has quit IRC | 12:56 | |
*** bnemec has quit IRC | 13:07 | |
*** bnemec has joined #openstack-keystone | 13:10 | |
*** bnemec has quit IRC | 13:16 | |
*** beekneemech has joined #openstack-keystone | 13:16 | |
*** beekneemech has quit IRC | 13:33 | |
*** bnemec has joined #openstack-keystone | 13:39 | |
*** bnemec has quit IRC | 13:47 | |
*** bnemec has joined #openstack-keystone | 13:51 | |
*** jaosorior has joined #openstack-keystone | 13:51 | |
*** bnemec has quit IRC | 13:55 | |
*** bnemec has joined #openstack-keystone | 13:58 | |
*** jaosorior has quit IRC | 14:16 | |
*** dave-mccowan has joined #openstack-keystone | 15:19 | |
*** dancn has quit IRC | 15:22 | |
*** dave-mccowan has quit IRC | 15:26 | |
*** ivve has quit IRC | 15:42 | |
*** tesseract has quit IRC | 15:56 | |
*** dklyle has quit IRC | 16:36 | |
*** dklyle has joined #openstack-keystone | 16:37 | |
*** fungi has quit IRC | 16:42 | |
*** fungi has joined #openstack-keystone | 16:43 | |
*** markvoelker has quit IRC | 16:44 | |
*** markvoelker has joined #openstack-keystone | 16:51 | |
*** spsurya has quit IRC | 17:14 | |
*** ivve has joined #openstack-keystone | 17:52 | |
*** gyee has joined #openstack-keystone | 18:06 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move get_trust enforcement to default policies https://review.opendev.org/676283 | 18:14 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move list_roles_for_trust enforcement to policies https://review.opendev.org/676284 | 18:14 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move get_role_for_trust enforcement to policies https://review.opendev.org/676287 | 18:14 |
cmurphy | while fixing those tests ^ i found our get trusts API exposes trust-nonexistence without enforcement :( | 18:15 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add federated support for get user https://review.opendev.org/448730 | 18:21 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add federated support for creating a user https://review.opendev.org/448755 | 18:21 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add federated support for updating a user https://review.opendev.org/448765 | 18:21 |
*** gagehugo has quit IRC | 19:09 | |
mordred | cmurphy: that doesn't seem like a feature | 19:30 |
cmurphy | mordred: no it is not good | 19:33 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add federated support for get user https://review.opendev.org/448730 | 20:08 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add federated support for creating a user https://review.opendev.org/448755 | 20:08 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add federated support for updating a user https://review.opendev.org/448765 | 20:08 |
*** gagehugo has joined #openstack-keystone | 20:46 | |
*** raildo has quit IRC | 21:13 | |
*** markvoelker has quit IRC | 21:26 | |
*** prometheanfire has joined #openstack-keystone | 22:02 | |
prometheanfire | hi, what's with the keystonemiddleware release? https://github.com/openstack/keystonemiddleware/compare/4.21.0...4.21.1 | 22:02 |
prometheanfire | no diff | 22:02 |
prometheanfire | because I'm looking wrong | 22:03 |
prometheanfire | :D | 22:03 |
cmurphy | prometheanfire: all good? | 22:05 |
cmurphy | there's no 4.21.1 | 22:05 |
prometheanfire | ya, exactly :D | 22:06 |
prometheanfire | have to make a fool of myself before figuring something out, it's a constant struggle | 22:07 |
cmurphy | the public internet is the best rubber duck | 22:07 |
prometheanfire | so it seems | 22:14 |
*** markvoelker has joined #openstack-keystone | 22:23 | |
*** ivve has quit IRC | 22:33 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Add protection tests for trusts API https://review.opendev.org/675720 | 22:43 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move list_trusts enforcement to default policies https://review.opendev.org/675807 | 22:43 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move delete_trust enforcement to default policies https://review.opendev.org/676277 | 22:43 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move get_trust enforcement to default policies https://review.opendev.org/676283 | 22:43 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move list_roles_for_trust enforcement to policies https://review.opendev.org/676284 | 22:43 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Move get_role_for_trust enforcement to policies https://review.opendev.org/676287 | 22:43 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Don't reveal trust existence to unauthorized users https://review.opendev.org/676528 | 22:43 |
cmurphy | this trusts api man | 22:43 |
*** markvoelker has quit IRC | 22:48 | |
*** tkajinam has joined #openstack-keystone | 22:50 | |
*** tyreymer has joined #openstack-keystone | 23:05 | |
*** xek has quit IRC | 23:14 | |
*** markvoelker has joined #openstack-keystone | 23:25 | |
*** markvoelker has quit IRC | 23:30 | |
kmalloc | yeah | 23:32 |
kmalloc | =/ | 23:32 |
kmalloc | it's... | 23:32 |
kmalloc | well... "historical" | 23:32 |
kmalloc | cmurphy: where is the unenforced trust non-existence? | 23:33 |
cmurphy | kmalloc: https://review.opendev.org/#/c/676528/1/keystone/api/trusts.py@150 | 23:36 |
cmurphy | 'identity:get_trust' is empty and doesn't do anything | 23:36 |
kmalloc | cmurphy: ah that is an issue | 23:36 |
cmurphy | enforcement is done in _trustor_trustee_only | 23:36 |
kmalloc | but it's not "unenforced" in the sense of enforcement being called | 23:36 |
kmalloc | i was worried i screwed up the enforced/unenforced API. | 23:37 |
kmalloc | i can enhance the check to not allow for "" policies | 23:37 |
cmurphy | kmalloc: no it's a pre-flask issue | 23:37 |
kmalloc | right | 23:37 |
kmalloc | because get_trust is empty, we call on "" | 23:37 |
kmalloc | we might want to make the enforcer not allow "" | 23:37 |
kmalloc | but the enforcer is called, which was my 1st concern. | 23:38 |
cmurphy | hmm in theory there could be a legitimate reason for an operator to set "" as a rule | 23:38 |
kmalloc | maybe | 23:38 |
cmurphy | but it's not appropriate for the trust defaults | 23:39 |
cmurphy | which is that that whole stack is about ^ | 23:39 |
kmalloc | bvut we can also detect default vs override | 23:39 |
kmalloc | i'm inclined to say defaults should never be "" | 23:39 |
cmurphy | i think i agree | 23:39 |
kmalloc | and that is a programming error, vs. override which is an operator concern (and maybe worth a warning/info line on load) | 23:40 |
kmalloc | future thinking of course | 23:40 |
*** tyreymer has quit IRC | 23:41 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!