[OpenStack-Infra] Proposal for improvements OpenstackID

Jimmy Mcarthur jimmy at tipit.net
Mon Apr 20 15:12:36 UTC 2015


Vlad,

In our opinion this would not be a good change. Validating the domain 
name is part of our security measures and would apply to both dev and 
production. If you just update your hosts file, you can get around this, 
or just make sure you're using a valid Top Level Domain.

Jimmy McArthur

Vladislav Kuzmin wrote:
> Hi, folks!
>
> I continue working with openstackid and found one things. When I send 
> request to OpenID endpoint I had exception in openstackid logs(Invalid 
> TLD).
> I spent more time for found this stuff. I propose use validation of 
> domain name only with production enviroment. But in development 
> enviroment we can disable that feature in OpenID helper 
> https://github.com/openstack-infra/openstackid/blob/master/app/libs/openid/helpers/OpenIdUriHelper.php#L374
> What do you think about it?
> _______________________________________________
> OpenStack-Infra mailing list
> OpenStack-Infra at lists.openstack.org
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-infra



More information about the OpenStack-Infra mailing list