keystone/releasenotes
Gage Hugo 8ab4eb27be Hide AccountLocked exception from end users
This change hides the AccountLocked exception from being returned
to the end user to hide sensitive information that a potential
malicious person could gain insight from.

The notification handler catches the AccountLocked exception as
before, but after sending the audit notification, it instead
bubbles up Unauthorized rather than AccountLocked.

Co-Authored-By: Samuel de Medeiros Queiroz <samueldmq@gmail.com>

Change-Id: Id51241989b22c52810391f3e8e1cadbf8613d873
Related-Bug: #1688137
(cherry picked from commit ac2631ae33)
2021-05-10 15:46:28 +00:00
..
notes Hide AccountLocked exception from end users 2021-05-10 15:46:28 +00:00
source Imported Translations from Zanata 2020-04-26 07:04:33 +00:00