Closed Bug 1487500 Opened 6 years ago Closed 6 years ago

Make the 'create-interactive' action safer

Categories

(Firefox Build System :: Task Configuration, task)

task
Not set
normal

Tracking

(firefox-esr60 fixed, firefox62 fixed, firefox64 fixed)

RESOLVED FIXED
mozilla64
Tracking Status
firefox-esr60 --- fixed
firefox62 --- fixed
firefox64 --- fixed

People

(Reporter: dustin, Assigned: dustin)

References

Details

Attachments

(2 files)

I started writing a new version of this in bug 1487444, and was a little more circumspect about whitelisting scopes. I'm not sure there's much else to change, but it warrants more thinking-about.
Some whitelisting of scopes, and some notes on security of the operation.
..and use this to allow create-interactive on level 3, but only for testers.
Brian, do you mind having a look at these r?'s?
Flags: needinfo?(bstack)
Comment on attachment 9008162 [details] Bug 1487500: allow context to be different based on parameters Brian Stack [:bstack] has approved the revision.
Attachment #9008162 - Flags: review+
Patch updated
Flags: needinfo?(bstack)
Comment on attachment 9008161 [details] Bug 1487500: improvements to create-interactive Brian Stack [:bstack] has approved the revision.
Attachment #9008161 - Flags: review+
reminder to self: try an interactive task on that try push, and note flake8 errors
Pushed by dmitchell@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/d601a7868c04 improvements to create-interactive r=bstack https://hg.mozilla.org/integration/autoland/rev/bdfd4802db0c allow context to be different based on parameters r=bstack
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla64
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: