Perform a security review of glean's `GleanDebugActivity`
Categories
(Toolkit :: Telemetry, defect, P1)
Tracking
()
Tracking | Status | |
---|---|---|
firefox67 | --- | affected |
People
(Reporter: Dexter, Assigned: Dexter)
References
Details
(Whiteboard: [telemetry:mobilesdk:m7])
The GleanDebugActivity
is shipped in the release version of the library to help with QA and problem diagnosis. However, other applications could manually start this activity and this might be a potential security problem.
This bug is for discussing any potential issue with this feature and, if required, take the appropriate actions to mitigate risks.
Assignee | ||
Updated•6 years ago
|
Assignee | ||
Comment 1•6 years ago
|
||
Hi Daniel! Is there any additional action that should be taken on our end with respect to the security review that we held together on March the 12th?
Can the document be shared here and this bug closed? Or do we need to do anything else to formally close the process?
Assignee | ||
Comment 2•6 years ago
|
||
All right, dumping the docs here. I'm closing this as FIXED, but I'll leave the ni? around for Dan:
Assignee | ||
Comment 3•6 years ago
|
||
(In reply to Alessio Placitelli [:Dexter] from comment #2)
All right, dumping the docs here. I'm closing this as FIXED, but I'll leave the ni? around for Dan:
Clearing the ni?: as discussed in the meeting (and highlighted in the docs), there was no major security risk there.
Description
•