branch whiteboards should be editable only by their owners
Bug #316773 reported by
Fabien Tassin
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Invalid
|
Low
|
Unassigned |
Bug Description
Anyone could modify the whiteboard of a branch hosted on LP.
It is a security issue. Only the owner/team should be able to do that.
Worse, the email sent to the owner(s) after the change does not contain a diff exposing the changes so it's not easy to check what has just been changed.
The point of whiteboards is that anyone can edit them.
If you want to store important information about your branches, your best bet is to edit the description field.