d74365969e
In new RBAC rules, all openstack services except ironic and keystone have dropped the system scope. - https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#phase-1 All the policy rules should be scoped to project and system scoped token should not be allowed to access the Cyborg APIs. As oslo.policy 4.4.0 enable the scope check and new defaults, it break cyborg tests and to fix that we need to drop the system scope from the cyborg policies. Ref: - https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/thread/6IDPXIXZ6FBKONNHFRU3ZPSXIIQJXUIE/ - https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/message/MPHSVG222OFHJL2AQD2A7CJGTH57SRCJ/ Change-Id: Iafbd5470e55e10ffb6bcddd232a698eb042d7eed |
||
---|---|---|
.. | ||
__init__.py | ||
base.py | ||
device_profiles.py |