summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJenkins <jenkins@review.openstack.org>2017-07-21 00:12:50 +0000
committerGerrit Code Review <review@openstack.org>2017-07-21 00:12:50 +0000
commit439872bc196260fe62e52235e0717040fd934394 (patch)
treec66f97635b028d17a4b8a145ffe6a7b6012cf799
parentfa76aa5f5df0b627ec13e04eb27357288978f702 (diff)
parent6c96675d63257d7ef2c27c5598c642efa7a25d08 (diff)
Merge "fix identity:get_identity_providers typo" into stable/ocata11.0.3
-rw-r--r--doc/source/policy_mapping.rst2
-rw-r--r--etc/policy.json2
-rw-r--r--etc/policy.v3cloudsample.json2
-rw-r--r--releasenotes/notes/bug-1703369-9a901d627a1e0316.yaml11
4 files changed, 14 insertions, 3 deletions
diff --git a/doc/source/policy_mapping.rst b/doc/source/policy_mapping.rst
index d3368fc..eed57fd 100644
--- a/doc/source/policy_mapping.rst
+++ b/doc/source/policy_mapping.rst
@@ -146,7 +146,7 @@ identity:remove_endpoint_group_from_project DELETE /v3/OS-EP-FILT
146 146
147identity:create_identity_provider PUT /v3/OS-FEDERATION/identity_providers/{idp_id} 147identity:create_identity_provider PUT /v3/OS-FEDERATION/identity_providers/{idp_id}
148identity:list_identity_providers GET /v3/OS-FEDERATION/identity_providers 148identity:list_identity_providers GET /v3/OS-FEDERATION/identity_providers
149identity:get_identity_providers GET /v3/OS-FEDERATION/identity_providers/{idp_id} 149identity:get_identity_provider GET /v3/OS-FEDERATION/identity_providers/{idp_id}
150identity:update_identity_provider PATCH /v3/OS-FEDERATION/identity_providers/{idp_id} 150identity:update_identity_provider PATCH /v3/OS-FEDERATION/identity_providers/{idp_id}
151identity:delete_identity_provider DELETE /v3/OS-FEDERATION/identity_providers/{idp_id} 151identity:delete_identity_provider DELETE /v3/OS-FEDERATION/identity_providers/{idp_id}
152 152
diff --git a/etc/policy.json b/etc/policy.json
index ddf2396..efa84e9 100644
--- a/etc/policy.json
+++ b/etc/policy.json
@@ -147,7 +147,7 @@
147 147
148 "identity:create_identity_provider": "rule:admin_required", 148 "identity:create_identity_provider": "rule:admin_required",
149 "identity:list_identity_providers": "rule:admin_required", 149 "identity:list_identity_providers": "rule:admin_required",
150 "identity:get_identity_providers": "rule:admin_required", 150 "identity:get_identity_provider": "rule:admin_required",
151 "identity:update_identity_provider": "rule:admin_required", 151 "identity:update_identity_provider": "rule:admin_required",
152 "identity:delete_identity_provider": "rule:admin_required", 152 "identity:delete_identity_provider": "rule:admin_required",
153 153
diff --git a/etc/policy.v3cloudsample.json b/etc/policy.v3cloudsample.json
index 9ba7173..6c5bc0b 100644
--- a/etc/policy.v3cloudsample.json
+++ b/etc/policy.v3cloudsample.json
@@ -174,7 +174,7 @@
174 174
175 "identity:create_identity_provider": "rule:cloud_admin", 175 "identity:create_identity_provider": "rule:cloud_admin",
176 "identity:list_identity_providers": "rule:cloud_admin", 176 "identity:list_identity_providers": "rule:cloud_admin",
177 "identity:get_identity_providers": "rule:cloud_admin", 177 "identity:get_identity_provider": "rule:cloud_admin",
178 "identity:update_identity_provider": "rule:cloud_admin", 178 "identity:update_identity_provider": "rule:cloud_admin",
179 "identity:delete_identity_provider": "rule:cloud_admin", 179 "identity:delete_identity_provider": "rule:cloud_admin",
180 180
diff --git a/releasenotes/notes/bug-1703369-9a901d627a1e0316.yaml b/releasenotes/notes/bug-1703369-9a901d627a1e0316.yaml
new file mode 100644
index 0000000..2d93d16
--- /dev/null
+++ b/releasenotes/notes/bug-1703369-9a901d627a1e0316.yaml
@@ -0,0 +1,11 @@
1---
2security:
3 - |
4 [`bug 1703369 <https://bugs.launchpad.net/keystone/+bug/1703369>`_]
5 There was a typo for the identity:get_identity_provider rule in the
6 default ``policy.json`` file in previous releases. The default value for
7 that rule was the same as the default value for the default rule
8 (restricted to admin) so this typo was not readily apparent. Anyone
9 customizing this rule should review their settings and confirm that
10 they did not copy that typo. More context regarding the purpose of this
11 backport can be found in the bug report.