Re: [openstack-dev] [Keystone] keystoneclient and project-less v3 tokens

2014-05-06 Thread Roman Bodnarchuk
Thanks for reply. I think I got the justifications for such an approach. BTW, is there a resource, which can be used to track support of Keystone v3 (and domain-based policies) among OS services? Are there some defined plans for moving whole OS to v3 and domains? -- Roman On 4/28/2014

Re: [openstack-dev] [Keystone] keystoneclient and project-less v3 tokens

2014-05-06 Thread Dolph Mathews
On Tue, May 6, 2014 at 3:17 AM, Roman Bodnarchuk roman.bodnarc...@indigitus.ch wrote: Thanks for reply. I think I got the justifications for such an approach. BTW, is there a resource, which can be used to track support of Keystone v3 (and domain-based policies) among OS services? Are

Re: [openstack-dev] [Keystone] keystoneclient and project-less v3 tokens

2014-04-27 Thread Jamie Lennox
On Thu, 2014-04-17 at 19:58 +0300, Roman Bodnarchuk wrote: Hello, I am trying to make sure that a user can't do anything useful with an unscoped token, and got to the following code in keystoneclient.middleware.auth_token: if _token_is_v2(token_info) and not