Do not permit open and delegated team to be project owners or security contacts

Bug #879103 reported by Curtis Hovey
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
High
Ian Booth

Bug Description

Lp must have a constraint to prevent open and delegated teams from owning project or being the principle security contact. Lp currently sends private or security bug information to the project maintainer or security contact. In the future, the default access policy rules for privacy and security will place the maintainer/registrant in the policy. User must not be permitted to place unvetted users in these roles.

A separate bug will track the 233 product and 1 distro that anyone can get access to confidential data or deface the project pages.

Related branches

Ian Booth (wallyworld)
Changed in launchpad:
status: Triaged → In Progress
assignee: nobody → Ian Booth (wallyworld)
Revision history for this message
Launchpad QA Bot (lpqabot) wrote :
tags: added: qa-needstesting
Changed in launchpad:
status: In Progress → Fix Committed
Curtis Hovey (sinzui)
tags: added: qa-ok
removed: qa-needstesting
Steve Kowalik (stevenk)
Changed in launchpad:
status: Fix Committed → Fix Released
William Grant (wgrant)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.