Activity log for bug #696954

Date Who What changed Old value New value Message
2011-01-03 20:28:09 Curtis Hovey bug added bug
2011-05-25 16:36:30 Curtis Hovey description project maintainers, drivers, bug supervisors, and security contacts should always have access to private bugs. They should not need a subscription to access their own project's private artefacts. At UDS-n, it was discovered that all the users interviewed thought users in project roles could see private bugs. Even experienced users thought this. This is sort of true since the project own sets the bug supervisor team and can make all teams in the other roles members of that team, but that does not give those roles access to the historic bugs. Even Canonical employees have been burned by this -- once they changed the bug supervisor, they learned that no one in the project roles could access the hundred of private bugs. project maintainers, drivers, and bug supervisors, should always have access to private bugs. They should not need a subscription to access their own project's private artefacts. At UDS-n, it was discovered that all the users interviewed thought users in project roles could see private bugs. Even experienced users thought this. This is sort of true since the project own sets the bug supervisor team and can make all teams in the other roles members of that team, but that does not give those roles access to the historic bugs. Even Canonical employees have been burned by this -- once they changed the bug supervisor, they learned that no one in the project roles could access the hundred of private bugs. This issue not relate to or propose changing how security bugs are handled. They will still require direct subscriptions and will continue to be brittle like private bug subscriptions are.
2011-09-19 07:09:12 Ian Booth launchpad: status Triaged In Progress
2011-09-19 07:09:16 Ian Booth launchpad: assignee Ian Booth (wallyworld)
2011-10-22 15:42:12 Andrea Corbellini bug added subscriber Andrea Corbellini
2011-11-21 16:10:02 Curtis Hovey launchpad: status In Progress Triaged
2011-11-21 16:10:04 Curtis Hovey launchpad: assignee Ian Booth (wallyworld)
2011-11-21 16:16:03 Curtis Hovey summary Allow persons in project roles to access private bugs Maintainers cannot specify who is in an access policy
2012-06-25 20:59:14 Curtis Hovey tags disclosure disclosure sharing
2012-08-17 20:37:34 Curtis Hovey launchpad: assignee William Grant (wgrant)
2012-08-17 21:27:46 Curtis Hovey launchpad: status Triaged In Progress
2012-08-23 23:23:39 William Grant launchpad: status In Progress Fix Released