Notifications about private branch linkages sent to unprivileged subscribers

Bug #345349 reported by William Grant
2
Affects Status Importance Assigned to Milestone
Launchpad itself
Invalid
High
Gavin Panella

Bug Description

Branch<->bug link changes are now sent, but the privileges of the recipient over the branch are not taken into account. I can't see the branch on the bug page, so emails shouldn't tell me about it.

Graham Binns (gmb)
Changed in malone:
importance: Undecided → High
milestone: none → 2.2.3
status: New → Triaged
Revision history for this message
Eleanor Berger (intellectronica) wrote :

Right, we should only send a notification to users who have access to the branch.

Changed in malone:
milestone: 2.2.3 → none
milestone: none → 2.2.3
Revision history for this message
Björn Tillenius (bjornt) wrote : Re: [Bug 345349] Re: Notifications about private branch linkages sent to unprivileged subscribers

On Thu, Mar 19, 2009 at 10:53:24AM -0000, Tom Berger wrote:
> Right, we should only send a notification to users who have access to
> the branch.

No, that's too complicated. We'd also need some kind of permission
checking for activity log entries.

We should check whether this is an issue for people using private teams
and branches. If it is, we'll simply not record the changes, at least
for now. Some time in the future we might have time to fix it in a
better way.

Revision history for this message
Gavin Panella (allenap) wrote :

As of bug #348520 we don't send any notifications or record activity for private branches. Ideally we should do as Tom suggests: only email and show bug history to those people with permission to see it.

Changed in malone:
importance: High → Medium
milestone: 2.2.3 → none
Graham Binns (gmb)
tags: added: story-better-bug-notification
Gary Poster (gary)
Changed in launchpad:
importance: Medium → High
tags: added: disclosure
removed: story-better-bug-notification
Curtis Hovey (sinzui)
Changed in launchpad:
status: Triaged → Invalid
Curtis Hovey (sinzui)
Changed in launchpad:
assignee: nobody → Gavin Panella (allenap)
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.