summaryrefslogtreecommitdiff
path: root/keystoneclient
Commit message (Collapse)AuthorAgeFilesLines
* Remove unused logzlyqqq2017-04-252-8/+0
| | | | Change-Id: I1fe2c1703b03eb1c8458c53bdd208a91ababf941
* Fix failing PY2 and PY3 gate jobsdineshbhor2017-03-222-2/+2
| | | | | | | | Please refer: http://logs.openstack.org/43/446943/1/check/gate-python-keystoneclient-python27-ubuntu-xenial/84b965d/console.html Closes-Bug: #1673761 Change-Id: Iefa74ffe8642f039a115e9ff4416c8f72d299317
* Merge "Add support for endpoint group CRUD"Jenkins2017-02-145-0/+310
|\
| * Add support for endpoint group CRUDSamuel de Medeiros Queiroz2017-02-115-0/+310
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The following API calls are made available: - POST /OS-EP-FILTER/endpoint_groups - GET /OS-EP-FILTER/endpoint_groups/{endpoint_group_id} - HEAD /OS-EP-FILTER/endpoint_groups/{endpoint_group_id} - PATCH /OS-EP-FILTER/endpoint_groups/{endpoint_group_id} - DELETE /OS-EP-FILTER/endpoint_groups/{endpoint_group_id} - GET /OS-EP-FILTER/endpoint_groups Partial-Bug: #1641674 Change-Id: I285eefe82152b178268f671e8800a0ff8c1511e4
* | Fix 12 warnings when building keystoneclient docsGage Hugo2017-02-095-7/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | While building keystoneclient docs, there are currently 12 warnings emitted that specify either: WARNING: more than one target found for cross-reference u'list' WARNING: more than one target found for cross-reference u'Auth' This change specifies the correct object for the docstring with "List" since there are many instances of "list" within keystoneclient and specifies the proper "Auth" object. With these changes, the warnings no longer appear. Change-Id: I4515429df38760700552d48fc570c03abf116f83
* | Use https for *.openstack.org referencesEric Brown2017-02-055-10/+11
| | | | | | | | | | | | | | The openstack.org pages now support https and our references to the site should by default be one signed by the organization. Change-Id: Ia6cdaf7fabd1c355df002aa07b0695610dde9cd1
* | Merge "Fix boto version strip regex"Jenkins2017-01-272-1/+40
|\ \
| * | Fix boto version strip regexMarounMaroun2017-01-272-1/+40
| | | | | | | | | | | | | | | | | | | | | | | | the current regex pattern will match incorrect strings like: Boto/2x0t2 Change-Id: I260f4e0d98f082172a3a67a1fbaa05da5369ea49 Closes-Bug: #1658639
* | | Allow Multiple Filters of the Same KeySamuel Pilla2017-01-242-1/+27
|/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Before, the way filters were passed in would not allow filtering on the same key. For example: keystone.users.list(name__contains='test', name__contains='user') This fails because of how kwargs handles key/value pairs. This patch allows using multiple values for the same filter. Example: keystone.users.list(name__contains=['test', 'user']) Specifying the only one filter value is still functional as expected. Co-Authored-By: Jeffrey Augustine <ja224e@att.com> Partially-Implements: bp pci-dss-query-password-expired-users Change-Id: I89cecf7e18974e7860ba0925840d6264168eabcb
* | Fix response body being omitted in debug mode incorrectlyTin Lam2017-01-172-2/+18
| | | | | | | | | | | | | | | | | | | | In debug mode, when a response's header Content-Type is set to "application/json" with a parameter, i.e., "application/json; charset=UTF-8". This patch set ignores the additional parameter and only match the mimetype. Change-Id: Ie8fcb1061e0e49b039436947524cfdc704c83846 Closes-Bug: #1656981
* | Only log application/json in session to start3.9.0Steve Martinelli2017-01-102-33/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | When whitelisting content types to debug print from session we chose application/json and application/text. application/text is not a real mime type, text is typically text/plain. Rather than guess at mime types only print application/json to start with, but make it easy for additional types to be added later. Adapted from keystoneauth: Ica5fee076cdab8b1d5167161d28af7313fad9477 Related-Bug: 1616105 Change-Id: Ieaa8fb3ea8d25e09b89498f23b70b18c0f6153f1
* | X-Serivce-Token should be hashed in the logTin Lam2017-01-092-2/+3
| | | | | | | | | | | | | | | | | | | | Currently, logs display the hash values of X-Auth-Token, Authorization, and X-Subject-Token, but not the value of the X-Service-Token. This patch set adds the X-Service-Token to the list of header fields to be hashed for logging purposes. Change-Id: Iaa3a27f4b6c3baf964fa0c71328ffe9df43b2c0a Closes-Bug: #1654847
* | Merge "Do not log binary data during request"Jenkins2017-01-082-7/+9
|\ \
| * | Do not log binary data during requestSteve Martinelli2017-01-062-7/+9
| |/ | | | | | | | | | | | | | | | | | | Do not log binary data during debug logging of a session. Replace the binary data with the string <binary_data> instead. sort of a backport of: I5184002f3a21c5e0ee510b21b9a7884c8dccd1e3 Change-Id: I07ddbc3967f297597542f1975004d94c490f6e6b Related-Bug: 1616105
* | Merge "remove hacking checks from keystoneclient"Jenkins2017-01-064-148/+0
|\ \
| * | remove hacking checks from keystoneclientSteve Martinelli2017-01-064-148/+0
| |/ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | the only hacking check in keystoneclient is related to older versions of oslo libraries, which are no longer supported by keystoneclient, for example: $ pip freeze | grep oslo.utils oslo.utils==3.18.0 $ python >>> import oslo.utils Traceback (most recent call last): File "<stdin>", line 1, in <module> ImportError: No module named oslo.utils >>> import oslo_utils >>> Let's just remove the hacking check since theres no way someone could incorrectly import the older versions. Closes-Bug: 1652458 Signed-off-by: Adam Williamson <awilliam@redhat.com> Change-Id: I14165903b46d2fc26e8c9de591917893f58516db
* | Merge "Prevent MemoryError when logging response bodies"Jenkins2017-01-053-14/+74
|\ \ | |/ |/|
| * Prevent MemoryError when logging response bodiesTobias Diaz2017-01-053-14/+74
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Response bodies are loaded into memory prior to being logged. Loading huge response bodies may result in a MemoryError. This patch proposes that only JSON and TEXT responses be logged, i.e when the Content-Type header is application/json or application/text. Responses that do not include or have a different Content-Type header will have their body omitted. This is a sort of backport of the fix for keystoneauth sessions, see I93b6fff73368c4f58bdebf8566c4948b50980cee Co-Authored-By: Samuel de Medeiros Queiroz <samueldmq@gmail.com> Closes-bug: 1616105 Change-Id: I8f43eee3a0b35041c6cf672e476f8151cf2f8d14
* | re-work inference rule bindingsSteve Martinelli2016-12-185-131/+383
| | | | | | | | | | | | | | | | | | | | | | | | | | | | - At least one API was not implemented (list_implied_roles) - the tests were lacking assertions and proper mocked responses - some of the functionality just didn't work (see bug) - returning Role objects instead of InferenceRule objects Related commits: - I80a40e88b571fe9b0eca3af8b705ea79f28eb904 - I66e863fb83f8dfcca2c48116d4377df060f402c3 Closes-Bug: 1647934 Change-Id: I7b449a93d7d4d3eb9ca857f6c1f78f884bad2534
* | Merge "Deprecate the generic client"Jenkins2016-12-083-0/+13
|\ \
| * | Deprecate the generic clientJamie Lennox2016-12-073-0/+13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The generic client has been around and unused for a really long time. I dont think it works at all and was never updated to support V3 concepts. Realistically we can probably just remove it and noone will notice, but give it a quick deprecation cycle. Closes-Bug: #1647930 Change-Id: Ie68c8995275bcd55aede49d8f4af4e0d172de089
* | | Use assertIsNone(...) instead of assertEqual(None, ...)chenaidong12016-12-082-2/+2
|/ / | | | | | | | | | | | | | | | | | | | | Refer to:http://docs.openstack.org/developer/hacking/#unit-tests-and-assertraises [H203] Use assertIs(Not)None to check for None (off by default) Unit test assertions tend to give better messages for more specific assertions. As a result, assertIsNone(...) is preferred over assertEqual(None, ...) and assertIs(None, ...) Change-Id: I4e60f3f7f3557080669b98cb48627acc40a72606
* | Refactor test_projectsRodrigo Duarte Sousa2016-12-051-37/+36
| | | | | | | | | | | | | | Do not reuse the environment's domain and project, create new ones for the tests. Change-Id: I91a5c1b42c0b31f548c1154a4ef028f45cf1cd24
* | Refactor test_credentialsRodrigo Duarte Sousa2016-12-051-13/+18
| | | | | | | | | | | | | | Do not reuse client's domain, create a new one to be used only by the test, which is destroyed later. Change-Id: I4e3bb11a92535650317a30e6a1854bfd161ee93f
* | Fix Failing tests with openssl >= 1.1.0Ondřej Kobližek2016-12-041-4/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | keystoneclient.tests.unit.test_cms.CMSTest.test_cms_verify keystoneclient.tests.unit.test_cms.CMSTest.test_cms_verify_token_no_files failing with: Command 'openssl' returned non-zero exit status 1 I think its OpenSSL >= 1.1 bug, which returns wrong exit code (1 instead of 2) if input file not exists. Change-Id: I776596487f305c759b88c0d4c604571c33c6ef70 Closes-Bug: #1646858
* | skip failing functional testSteve Martinelli2016-12-041-0/+3
| | | | | | | | Change-Id: If3894679d21709ab813b4675c4bc721a3987596a
* | Merge "Fix missing service_catalog parameter in Client object"3.8.0Jenkins2016-12-013-1/+20
|\ \
| * | Fix missing service_catalog parameter in Client objectMikhail Nikolaenko2016-08-053-1/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Return None if service_catalog parameter does not exist. service_catalog is the property and it is not initialized on object creation. service_catalog tries to get value from auth_ref and raises AttributeError exception if auth_ref is not initialized. It worked before we introduced sessions, because authentication happened on client instantiation. Now, when sessions are used, auth_ref is not initialized until the first request. This change adds try-catch block in service_catalog property to catch this error. Change-Id: I58eb888f0989241f9e5626564bd48d901b324d36 Closes-Bug: #1508374
* | | Merge "Pass allow_expired to token validate"Jenkins2016-11-292-4/+31
|\ \ \
| * | | Pass allow_expired to token validateJamie Lennox2016-11-292-4/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Allow passing the allow_expired flag to v3 token validation to support extended service to service communication. Implements bp: allow-expired Change-Id: Ia1763fedc1838ad3c58c7f8f98f00b7eaad55a5c
* | | | Replace 'assertFalse(a in b)' with 'assertNotIn(a, b)'howardlee2016-11-182-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | Trivial fix. Change-Id: I818245eaa9e63322b1c6de049368aa4e09b01b4b
* | | | Fix some spelling mistaks in base.py & auth.pyzhangyanxian2016-11-172-3/+3
| | | | | | | | | | | | | | | | | | | | TrivialFix:"dependant" should be "dependent" Change-Id: I276876e5909ac5958c9e0e911b45e813b8104702
* | | | Merge "Fix typo in access.py"Jenkins2016-11-171-1/+1
|\ \ \ \
| * | | | Fix typo in access.pyzhangyanxian2016-11-161-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | TrivalFix Change-Id: I44250004eb56b579c227874e4b08e358e8dd8712
* | | | | Refactor test_domain_configsRodrigo Duarte Sousa2016-11-161-13/+18
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | Do not reuse the environment domain, create a new one to be fully controlled by the test cases. Change-Id: Idb894da724e252b01405fc937c021fd8981ee090
* | | | Merge "Do not add last_request_id"3.7.0Jenkins2016-11-141-2/+0
|\ \ \ \
| * | | | Do not add last_request_idBoris Bobrov2016-11-101-2/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It is untested and doesn't work for a while. It also causes a failure when the method is used by other client or by keystoneclient itself. Change-Id: Icdd53936a107933e275acd43b5ebe94b8d04bc4b Closes-Bug: 1637530
* | | | | Remove revocation event codeBoris Bobrov2016-11-102-318/+0
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | It was added in 2014 and was supposed to be used for sharing revocation events with keystonemiddleware. It was never finished, and the code is untested and is not used by anything. Change-Id: I905b7b3d95274b3c501b1e584e492eefa72158c1
* | | | Merge "Remove unauthenticated functions"Jenkins2016-11-101-24/+0
|\ \ \ \
| * | | | Remove unauthenticated functionsJamie Lennox2016-08-241-24/+0
| | |_|/ | |/| | | | | | | | | | | | | | | | | | These were used by the shell which has since been removed. Change-Id: If329da4499b76799356e79099f86a4afdebb00ce
* | | | Fix typo in httpclient.pyzhangyanxian2016-11-081-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | TrivialFix Change-Id: I248e0548fc0242d9f164df901be3c87ae3a75413
* | | | Merge "Increase readability of 'find()' method and small improvements"Jenkins2016-11-034-11/+12
|\ \ \ \
| * | | | Increase readability of 'find()' method and small improvementsArthur Miranda2016-10-214-11/+12
| | |/ / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | Assigments replaced with argument assigment: endpoints.py, service_catalog.py Note added: 'original_ip' value is never used: session.py Refactor 'find()' method to increase readability: base.py Change-Id: I469331b123fdf03e9e7c5d93e1c95da57d30fbbe
* | | | Support domain-specific configuration managementHenry Nash2016-11-025-0/+350
|/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Provide support for the domain-specific configuration storage available via the REST API. Domain configs are JSON blobs and we have fine grained control on them via the Identity API. This fine grained control is not defined yet in the client, though - for now, we can manage everything like Python dictionaries and use operations like "update" whenever we want to delete a specific group or option. This approach is similar to what is done in the federation mapping API to handle mapping rules. Functional tests are also included, this is useful to check if the new feature works in an integration environment. Co-Auhtored-By: Henry Nash <henryn@linux.vnet.ibm.com> Co-Authored-By: Rodrigo Duarte <rduartes@redhat.com> Closes-Bug: 1433306 Partially Implements: blueprint domain-config-ext Change-Id: Ie6795b8633fed38c58b79250c11c9a045b7f95a4
* | | Merge "TrivialFix: Using assertIsNone() instead of assertEqual(None)"Jenkins2016-10-201-1/+1
|\ \ \
| * | | TrivialFix: Using assertIsNone() instead of assertEqual(None)Anh Tran2016-09-271-1/+1
| | | | | | | | | | | | | | | | Change-Id: I1e3c101b6d8f21bbf98c98f5451334cc1b524d5b
* | | | Merge "Use exceptions from Keystoneauth"Jenkins2016-10-1411-33/+39
|\ \ \ \
| * | | | Use exceptions from KeystoneauthJamie Lennox2016-08-2411-33/+39
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As keystoneclient and other services rely more on keystoneauth we should assume that keystoneauth is our base auth library, not keystoneclient and start to default to the objects provided from there. This will make it easier to remove these objects when the time comes. For the session independant parts of keystoneclient we should use the exception names as provided by keystoneauth instead of the aliases in keystoneclient. Change-Id: Ic513046f8398a76c244e145d6cc3117cdf6bb4cd
* | | | | Remove redundant variable declarationGeorge Tian2016-10-091-2/+0
| | | | | | | | | | | | | | | | | | | | Change-Id: Ifc80f889f82e9853132b8f91e63cc53cfc476ac6
* | | | | Merge "Use AUTH_INTERFACE object from keystoneauth"Jenkins2016-10-0510-23/+26
|\ \ \ \ \ | |/ / / /