Closed Bug 280135 Opened 20 years ago Closed 18 years ago

checksetup.pl should ask confirmation for the default regexp concerning the editbugs group

Categories

(Bugzilla :: Installation & Upgrading, enhancement)

2.19.2
enhancement
Not set
normal

Tracking

()

RESOLVED WONTFIX

People

(Reporter: LpSolit, Assigned: zach)

Details

By default, all users have editbugs privs, due to the default .* regexp for this
group. When running checksetup.pl (for the first time?), it should ask the
administrator if he wants to keep that regexp or enter a new one.

That way, the admin cannot miss that point which may appear as a security hole
(assuming everyone is free to create an account on this installation).
I don't want to add any new "questions" to checksetup.pl.

Perhaps the initial login page that you created for new admins could warn about this.
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.