Closed Bug 1831632 Opened 3 years ago Closed 3 years ago

Update group membership report to more prominently display users are in groups that not Mozilla email addresses (i.e. personal accounts)

Categories

(bugzilla.mozilla.org :: General, enhancement)

enhancement

Tracking

()

RESOLVED FIXED

People

(Reporter: dkl, Assigned: dkl)

References

Details

Attachments

(1 file)

Currently you can make the report show, for example, all users who have access to the mozilla-employee-confidential permission group. But it is not obvious which ones are not mozilla.com/mozillafoundation.org/etc. accounts and are instead personal email accounts.

Most of the Mozilla related groups have a regular expression associated with them that automatically places the account in the group if the email address matches.

We want to able see the non-mozilla accounts that have mozilla permissions and show the ones that are disabled and not disabled.

In ye olden days we have a report that was mailed out that gave this information but we no longer run the script that generates the report.

HR sends out API requests to various systems to disable accounts when an employee leaves and when the account is the same as the Mozilla primary address this process mostly works fine. But when the user is employed or NDA'ed and they are using their personal account, if they do not have that account associated as a bugmail address in LDAP, the proper closure will not happen and the account is left empowered when it should not be.

Moving to a SSO system for Bugzilla and requiring all employees, etc to use SSO will help with this somewhat but their is not a timeframe for when that will happen.

Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: