Maintainers cannot specify who is in an access policy

Bug #696954 reported by Curtis Hovey
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
High
William Grant

Bug Description

project maintainers, drivers, and bug supervisors, should always have access to private bugs. They should not need a subscription to access their own project's private artefacts.

At UDS-n, it was discovered that all the users interviewed thought users in project roles could see private bugs. Even experienced users thought this. This is sort of true since the project own sets the bug supervisor team and can make all teams in the other roles members of that team, but that does not give those roles access to the historic bugs. Even Canonical employees have been burned by this -- once they changed the bug supervisor, they learned that no one in the project roles could access the hundred of private bugs.

This issue not relate to or propose changing how security bugs are handled. They will still require direct subscriptions and will continue to be brittle like private bug subscriptions are.

Revision history for this message
Robert Collins (lifeless) wrote :

I think 'project roles' needs to be defined much more clearly - 'blueprint driver' wouldn't imply 'can see CVE vulnerabilities' IMO.

Curtis Hovey (sinzui)
description: updated
Ian Booth (wallyworld)
Changed in launchpad:
status: Triaged → In Progress
assignee: nobody → Ian Booth (wallyworld)
Curtis Hovey (sinzui)
Changed in launchpad:
status: In Progress → Triaged
assignee: Ian Booth (wallyworld) → nobody
Curtis Hovey (sinzui)
summary: - Allow persons in project roles to access private bugs
+ Maintainers cannot specify who is in an access policy
Curtis Hovey (sinzui)
tags: added: sharing
Revision history for this message
Curtis Hovey (sinzui) wrote :

William, mark this fix released when we enter the Sharing beta.

Changed in launchpad:
assignee: nobody → William Grant (wgrant)
Curtis Hovey (sinzui)
Changed in launchpad:
status: Triaged → In Progress
William Grant (wgrant)
Changed in launchpad:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.