Keystone V2 Changes

Description

Kv2 needs to send tenant and tenant roles to back end filters. Goal of story is to capture tenant roles for ticketing rbac.

Info is already passed as header with the whole service catalog. Shouldn't be a requirement to continue to pass the header to OS. The OS shouldn't care about this data unless explicitly told to do so

Acceptance Criteria:

  • A request header exists that points back to the items in the local datastore where this information is.

  • Docs are updated to reflect that this feature requires Kv2 cache to be configured 'on' for this feature to work.

  • Cache misses due to ttl milliseconds will be handled as token expiration.

    • Kv2 filter should add response header www-authenticate if it sees a 401 from downstream filters / origin service.

Environment

None

Attachments

1
100% Done
Loading...

Activity

Done
Pinned fields
Click on the next to a field label to start pinning.

Details

Assignee

Reporter

Capitalizable

True

Story Points

Time remaining

0h

Sprint

Fix versions

Priority

Created May 18, 2017 at 3:22 PM
Updated June 8, 2017 at 4:04 PM
Resolved June 7, 2017 at 6:38 PM