Disabling identity providers doesn't work

Bug #1416459 reported by Marek Denis
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
High
Marek Denis

Bug Description

During federated authentication we don't check if the identity provider is disabled or not.

Changed in keystone:
assignee: nobody → Marek Denis (marek-denis)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/151683

Changed in keystone:
status: New → In Progress
Revision history for this message
Brant Knudson (blk-u) wrote :

Looks like a security vulnerability.

Revision history for this message
Steve Martinelli (stevemar) wrote :

and a backport potential

Changed in keystone:
importance: Undecided → High
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/151683
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=ddd3a4f5b1a60498966b2a6067c19862ae8ad953
Submitter: Jenkins
Branch: master

commit ddd3a4f5b1a60498966b2a6067c19862ae8ad953
Author: Marek Denis <email address hidden>
Date: Fri Jan 30 16:59:34 2015 +0100

    During authentication validate if IdP is enabled

    During federated authentication we don't check if identity providers are
    enabled and always issue unscoped and scoped tokens. This patch fixes
    that.

    Change-Id: I377b37715c913c3fb85925fad418402fd88b3bd1
    Closes-Bug: #1416459

Changed in keystone:
status: In Progress → Fix Committed
Changed in keystone:
milestone: none → kilo-2
Thierry Carrez (ttx)
Changed in keystone:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in keystone:
milestone: kilo-2 → 2015.1.0
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.