Users should not be able to approve their own approval requests

RESOLVED FIXED

Status

()

Firefox
Normandy Server
P2
normal
RESOLVED FIXED
2 years ago
6 months ago

People

(Reporter: mkelly, Unassigned)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

2 years ago
A user who creates a new approval request should not be able to approve their own request. This is to prevent the compromise of a single account from compromising Normandy itself by requiring two separate accounts to approve approval requests.
(Reporter)

Updated

2 years ago
Blocks: 1282505
(Reporter)

Updated

2 years ago
No longer blocks: 1282505
This was fixed a while ago.
Status: NEW → RESOLVED
Last Resolved: 6 months ago
Resolution: --- → FIXED

Updated

6 months ago
Product: Shield → Firefox
You need to log in before you can comment on or make changes to this bug.