Can get status of secure bugs by referencing bug
Categories
(Bugzilla :: Bugzilla-General, defect)
Tracking
()
People
(Reporter: mymindstorm, Unassigned)
Details
User Agent: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:75.0) Gecko/20100101 Firefox/75.0
Steps to reproduce:
- Create a restricted bug by checking the security box
- Reference the restricted bug in a public bug
- Logout
- Hover over the restricted bug link and you should see the status and title of the restricted bug
Example: https://bugzilla-dev.allizom.org/show_bug.cgi?id=1396254
Actual results:
I was able to see the title and status of the restricted bug.
Expected results:
I should not be able to view any details of the restricted bug.
| Reporter | ||
Updated•5 years ago
|
| Reporter | ||
Comment 1•5 years ago
|
||
I made a mistake in the report, you cannot see the title of a restricted bug, just the status.
Comment 2•5 years ago
|
||
So what? What does it tell you that a bug with some number is FIXED or not if you can't tell what that bug is about.
| Reporter | ||
Comment 3•5 years ago
|
||
Pretty much. You can't get the bug status from directly going to the bug or via the API.
Comment 4•5 years ago
|
||
Because this bug's Severity is normal and has not been changed, and this bug's priority is -- (none,) indicating it has has not been previously triaged, the bug's Severity is being updated to -- (default, untriaged.)
Description
•