<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>openstack/keystone — Stackers Network</title>
    <link>https://stackers.network/projects/openstack-keystone/</link>
    <description>Weekly code-activity digest for openstack/keystone from Stackers Network.</description>
    <item>
      <title>openstack/keystone — Week of 2026-06-13</title>
      <link>https://stackers.network/projects/openstack-keystone/2026-06-13</link>
      <guid>https://stackers.network/projects/openstack-keystone/2026-06-13</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <description>Security disclosures. The week is dominated by a coordinated batch of CVE fixes, each landed on master and a stable branch. CVE-2026-42999 closes an RBAC policy bypass reachable through JSON body and query-string filters — the largest of the set at ~430 lines per landing…</description>
      <content:encoded><![CDATA[<p><strong>Security disclosures.</strong> The week is dominated by a coordinated batch of CVE fixes, each landed on master and a stable branch. CVE-2026-42999 closes an RBAC policy bypass reachable through JSON body and query-string filters — the largest of the set at ~430 lines per landing (<a href="https://review.opendev.org/c/openstack/keystone/+/990504">990504</a>). CVE-2026-43000 forbids trust operations initiated with application credentials, CVE-2026-44394 preserves <code translate="no">expires_at</code> when rescoping federated tokens so they cannot outlive their origin, and CVE-2026-42998 plugs a user-impersonation path through application credentials. A related hardening blocks app-cred tokens from authorizing OAuth1 request flows.</p>
<p><strong>Delegation boundaries.</strong> Alongside the CVEs, a substantial ~1,000-line change enforces the delegation project boundary for delegated tokens, landing on master and a stable branch. A separate fix tightens the EC2 credential paths to enforce the application-credential project boundary, closing a parallel gap in the same area.</p>
<p><strong>Federation tooling and CI.</strong> The devstack Keycloak client gains an audience mapper to support federated-token testing, and a stable-only CI tweak reuses the already-defined upper-constraints definition.</p>]]></content:encoded>
    </item>
    <item>
      <title>openstack/keystone — Week of 2026-06-06</title>
      <link>https://stackers.network/projects/openstack-keystone/2026-06-06</link>
      <guid>https://stackers.network/projects/openstack-keystone/2026-06-06</guid>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <description>Security fixes. The week is dominated by a coordinated batch of CVE remediations, with most changes landing as master/backport pairs. A new enforcement of the delegation project boundary for delegated tokens is the largest piece at roughly 1,000 lines (990490). Alongside it…</description>
      <content:encoded><![CDATA[<p><strong>Security fixes.</strong> The week is dominated by a coordinated batch of CVE remediations, with most changes landing as master/backport pairs. A new enforcement of the delegation project boundary for delegated tokens is the largest piece at roughly 1,000 lines (<a href="https://review.opendev.org/c/openstack/keystone/+/990490">990490</a>). Alongside it: RBAC policy bypass via JSON body and query filters is closed off (CVE-2026-42999), trust operations are forbidden when acting through application credentials (CVE-2026-43000), <code translate="no">expires_at</code> is now preserved when rescoping federated tokens (CVE-2026-44394), and user impersonation through application credentials is blocked (CVE-2026-42998). A separate hardening change also stops restricted application credentials from minting EC2 credentials via <code translate="no">/credentials</code>, with dedicated tests for the app-cred guard.</p>
<p><strong>LDAP identity.</strong> Pagination in the LDAP backend was reworked so listings return all users beyond <code translate="no">page_size</code> rather than truncating at the first page.</p>
<p><strong>CI.</strong> A single fix patches stable/2025.2 jobs — nodeset, a test skip, and the Keycloak audience mapper — to unblock the branch that received this week's CVE backports.</p>]]></content:encoded>
    </item>
  </channel>
</rss>
