diff options
| author | Dan Prince <dprince@redhat.com> | 2012-07-12 13:48:43 -0400 |
|---|---|---|
| committer | Dan Prince <dprince@redhat.com> | 2012-07-12 14:49:50 -0400 |
| commit | 86177dff68c45a459644f9953bef4c3afbed24ff (patch) | |
| tree | 4cc3cace93f9f32724ca463b63e7374af5070397 /keystone/openstack | |
| parent | 2a909ee83d23a38e2ae7ca8002e570788674521c (diff) | |
Prevent service catalog injection in auth_token.
Updates the auth_token middleware to explicitly prevent
X-Service-Catalog headers from being injected into responses.
In general Keystone would override these with its own service
catalog... however since X-Service-Catalog is optional and
not all implementations/calls return it is good to be safe and
just remove incoming X-Service-Catalog headers if they are set.
Fixes LP Bug #1023998.
Change-Id: I9497937abd1b434b42b40bc943a508dd7f1a3585
Diffstat (limited to 'keystone/openstack')
0 files changed, 0 insertions, 0 deletions
