Hi,

There is a use case where keystone seems to behave improperly. Not sure if
it is a bug, please do comment.

 A user has 'admin' role for two tenants. When I remove 'admin' role
association from one tenant for the user, the user's token got earlier for
other tenant becomes invalid.

However if I get a new token using the second tenant it works.

In more detail

user 'test' has 'admin' role in tenant 't1' and 't2'.

revoke 'admin' role for user 'test' for tenant 't1'

The user's token for 't2' become invalid.

Is this valid behavior.

Thank you,
_______________________________________________
Mailing list: http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack
Post to     : openstack@lists.openstack.org
Unsubscribe : http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack

Reply via email to