
Publishing a fully hydrated context object in a notification would give someone with access to that notification the ability to impersonate the original actor through inclusion of sensitive fields. Now, instead, we pare down the context object to the bare minimum before passing it for serialization in notification workflows. Related-bug: 2030976 Change-Id: Ic94323658c89df1c1ff32f511ca23502317d0f00
Team and repository tags
Oslo Messaging Library
The Oslo messaging API supports RPC and notifications over a number of different messaging transports.
- License: Apache License, Version 2.0
- Documentation: https://docs.openstack.org/oslo.messaging/latest/
- Source: https://opendev.org/openstack/oslo.messaging
- Bugs: https://bugs.launchpad.net/oslo.messaging
- Release notes: https://docs.openstack.org/releasenotes/oslo.messaging/
Description
Languages
Python
99.8%
Shell
0.2%