Complete multiproject. Adding admin query string: FORCE,ADMIN,PUBLIC,SET_PROJECT
Change-Id: I96bbb050ea8ade55edb948b925127049882ff191
Signed-off-by: tierno <alfonso.tiernosepulveda@telefonica.com>
diff --git a/osm_nbi/auth.py b/osm_nbi/auth.py
index 9171c94..fcebad4 100644
--- a/osm_nbi/auth.py
+++ b/osm_nbi/auth.py
@@ -55,6 +55,7 @@
Authorization. Initially it should support Openstack Keystone as a
backend through a plugin model where more backends can be added and a
RBAC model to manage permissions on operations.
+ This class must be threading safe
"""
periodin_db_pruning = 60 * 30 # for the internal backend only. every 30 minutes expired tokens will be pruned
@@ -480,7 +481,8 @@
now = time()
session = self.tokens_cache.get(token_id)
if session and session["expires"] < now:
- del self.tokens_cache[token_id]
+ # delete token. MUST be done with care, as another thread maybe already delete it. Do not use del
+ self.tokens_cache.pop(token_id, None)
session = None
if session:
return session
@@ -501,7 +503,7 @@
if self.config["global"].get("test.user_not_authorized"):
return {"id": "fake-token-id-for-test",
"project_id": self.config["global"].get("test.project_not_authorized", "admin"),
- "username": self.config["global"]["test.user_not_authorized"]}
+ "username": self.config["global"]["test.user_not_authorized"], "admin": True}
else:
raise