Comment 11 for bug 1562175

Revision history for this message
Travis McPeak (travis-mcpeak) wrote :

OK, trying to understand the impact. From the bug description:

"A user can cause an existing object in another account to be copied - when that user is not authorized for that account." Does this mean that there is a path for a user to be granted access to a container or object they shouldn't have? I didn't get that from reading the rest of the bug description, but if that's the case this seems pretty bad.

Not saying we don't want to fix in the open, just want us to have eyes wide open to WHAT we're fixing in the open.