Closed Bug 684974 Opened 13 years ago Closed 12 years ago

create new group: mozilla-services-security and use that for the Mozilla Services sec bug group.

Categories

(bugzilla.mozilla.org :: Administration, task)

Production
task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: mconnor, Assigned: dkl)

References

Details

rather than grant access to client-services-security much more widely, I'd like a new group created and used in place of client-services-security for all sec bugs under Mozilla Services

Once this is created, the following groups should inherit access:

security-group 
services-team
infra-services
done
Assignee: nobody → dkl
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
This was not set up correctly. extensions/BMO/lib/Data.pm is missing additions related to the new security group, such as assignment to product, allowing non-group members to file bugs, and where e-mails should go. Group creation takes a lot of thought and effort, so please be careful.

How was the group itself created? Nobody (even admins) should have direct bless privs. Should all go through the inherited access groups.
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Thanks for catching that Reed. I will add some text to the wiki to remind myself/others about changes that need to be addressed in the future.

Mike, can you tell me an email address that you wanted to be added to the CC list of any bugs that have the new mozilla-services-security group added? For example when people place a bug into the 'webtools-security' group, we have it configured to automatically add 'webtool-security@mozilla.org' to the CC list. This way people 
associated with that address will see the bug come up on their radars.

Once I get the address, or you decide you do not need one, I will get these fixes in place for the next push.

dkl
ping mconnor

(In reply to David Lawrence [:dkl] from comment #3)
> Mike, can you tell me an email address that you wanted to be added to the CC
> list of any bugs that have the new mozilla-services-security group added?
> For example when people place a bug into the 'webtools-security' group, we
> have it configured to automatically add 'webtool-security@mozilla.org' to
> the CC list. This way people 
> associated with that address will see the bug come up on their radars.
> 
> Once I get the address, or you decide you do not need one, I will get these
> fixes in place for the next push.
ping mconner
ping mconner
mconnor, can you comment on my questions in comment 3 please?

Thanks
dkl
Sigh, I suck.

No email address is required for this group, most of us already watch most of the bugmail, and we triage regularly.
Status: REOPENED → ASSIGNED
Committed and will be in the next push.

Committing to: bzr+ssh://dlawrence%40mozilla.com@bzr.mozilla.org/bmo/4.0
modified extensions/BMO/lib/Data.pm
Committed revision 8081.

dkl
Status: ASSIGNED → RESOLVED
Closed: 13 years ago12 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.