keystone/etc
Steve Martinelli ef48072d94 Fix cloud_admin rule and ensure only project tokens can be cloud admin
The current rule fails to load with oslo.policy, the correct
value used to determine the admin project for the cloud_admin should
simply be: `is_admin_project:True`, since that is what is stored
in oslo.context.

This problem was masking a more serious issue that domain admin tokens
could be misinterpreted as cloud admin tokens.

Change-Id: I3ea562c01e06e6c519fdaec3ab6e1dac204ced71
Closes-Bug: 1547684
Closes-Bug: 1651989
2016-12-23 09:31:08 +00:00
..
default_catalog.templates Update sample catalog templates 2015-11-04 10:06:45 +08:00
keystone-paste.ini Add healthcheck middleware to pipelines 2016-11-09 19:39:41 +00:00
keystone.conf.sample Update sample keystone.conf for Newton 2016-09-07 20:41:47 +00:00
logging.conf.sample Generate apache-style common access logs 2013-01-31 08:16:21 -06:00
policy.json Implement password requirements API 2016-12-15 19:51:41 +00:00
policy.v3cloudsample.json Fix cloud_admin rule and ensure only project tokens can be cloud admin 2016-12-23 09:31:08 +00:00
sso_callback_template.html Add WebSSO support for federation 2015-02-18 23:35:30 -05:00