Closed
Bug 737883
Opened 14 years ago
Closed 11 years ago
Bug 731044 breaks gmail threading of bugs
Categories
(bugzilla.mozilla.org :: Extensions, defect)
Tracking
()
RESOLVED
FIXED
People
(Reporter: khuey, Assigned: dkl)
References
Details
All of the "secure bug updated" messages end up in a single thread together, instead of a thread per bug like bugmail normally is.
this isn't a blocker, dropping priority.
given the significant usability issues we've seen with the subject being sanitised, i'd be interested to hear the security team's thoughts about leaving the subject untouched, and just encrypting the body.
Severity: blocker → major
| Reporter | ||
Comment 2•14 years ago
|
||
IMO it's a blocker for me. It makes keeping track of the secure bugs I need to look at impossible.
(In reply to Kyle Huey [:khuey] (khuey@mozilla.com) from comment #2)
> IMO it's a blocker for me. It makes keeping track of the secure bugs I need
> to look at impossible.
understood.
there's been quite a few issues raised about sanitising the subject, this one by far the most serious due to its crippling impact on workflow.
i'm unable to reproduce this; gmail is threading securemail messages correctly for me.
| Reporter | ||
Comment 5•14 years ago
|
||
Comment 6•14 years ago
|
||
There may be two issues here.
Bugs that are opened are sent to the security group members when opened. Those bugs don't get encrypted because they are new and the kludge to send them to the group doesn't seem to have a key (and we wouldn't have it anyway).
The other is the lack of a subject line in e-mail.
I'm of the mind that maybe we want to have the subject in the email but I'll want to discuss it with others. There is discussion in another bug that if you're using s/mime, which includes an encrypted subject in the body, of getting that set up to be pulled into the subject of the message when decrypted somehow.
| Assignee | ||
Comment 7•14 years ago
|
||
I have been able to recreate this issue using my dev instance and my gmail account. What I can observe is Gmail is treating the part inside of the brackets as special and not using it when determining message threading. So it does not see the bug id in the subject line and therefore thinks all of the "(Secure bug updated)" subjects are from the same conversation. If I update the SecureMail extension to remove the square brackets so the subject looks like "Bug 12345 - (Secure bug updated) the each bugs emails are threaded together properly. For normal bugs where the summaries are normally unique this issue is not noticeable.
So in summary we have two choices:
1. Talk to Google and find out why text between square brackets are not being considered when grouping messages.
2. Update the SecureMail extension to remove the square brackets from the message Subject line.
3. Send the real bug summary in the message Summary line which is still being discussed about its impact in doing so.
From globs experience, #1 is pretty futile, #3 is undecided. So #2 is a quick fix for now.
dkl
(In reply to Al Billings [:abillings] from comment #6)
> Bugs that are opened are sent to the security group members when opened.
> Those bugs don't get encrypted because they are new and the kludge to send
> them to the group doesn't seem to have a key (and we wouldn't have it
> anyway).
that sounds like a different issue than the one discussed here, please file a new bug.
off the top of my head i can't think of any technical blocker that would prevent this from happening.
> I'm of the mind that maybe we want to have the subject in the email but I'll
> want to discuss it with others.
thanks, i'm very interested in the outcome of that discussion.
> There is discussion in another bug that if
> you're using s/mime, which includes an encrypted subject in the body, of
> getting that set up to be pulled into the subject of the message when
> decrypted somehow.
correct, however this subject isn't used to replace the non-encrypted subject in all email clients (the rfc says the client _may_ not _should_ do this). thunderbird doesn't behave this way :(
it also doesn't help people who are using pgp encryption, or those who don't, or can't, provide a key (such as gmail and some accounts which are distribution lists).
for clarity i've duplicated this response on bug 737401
(In reply to David Lawrence [:dkl] from comment #7)
> I have been able to recreate this issue using my dev instance and my gmail
> account. What I can observe is Gmail is treating the part inside of the
> brackets as special and not using it when determining message threading. So
> it does not see the bug id in the subject line and therefore thinks all of
> the "(Secure bug updated)" subjects are from the same conversation.
odd.. this isn't the experience i'm getting; gmail is threading emails correctly for me, see http://i.imgur.com/KZ0Uk.png
> 1. Talk to Google and find out why text between square brackets are not
> being considered when grouping messages.
.. in some circumstances (urgh!)
> 2. Update the SecureMail extension to remove the square brackets from the
> message Subject line.
i'm not a fan of this proposal -- the [Bug nnn] format in the subject is something that people scan for (i for one do when i'm looking at my email); it's something that clearly identifies bugmail. we even have code within bugzilla which relies on this.
| Reporter | ||
Comment 9•14 years ago
|
||
So what's the plan for moving forward here?
Comment 11•14 years ago
|
||
This has caused me to miss a whole bunch of security bugmail (I didn't realize this was happening), and is really impacting my ability to stay up to date with security bugs.
Can we remove the brackets immediately, as a spot fix?
Comment 12•14 years ago
|
||
ok, let's go ahead with changing the brackets :(
we'll have to be careful to ensure we don't break code (we should add an x-bugzilla-bug-id header and use that instead of parsing the subject).
Comment 13•14 years ago
|
||
Other possible stop-gaps that might be less risky would be to include a hash of the original summary, or repeat the bug number outside of the brackets (instead of just removing them).
| Assignee | ||
Comment 14•14 years ago
|
||
Added workaround that puts the bug id in the subject text to see if this fixes the gmail threading issue for those affected.
[Bug XXXXXX] (Secure bug XXXXXX updated)
I admit this is not optimal and has redundant data and we will remove this once we have a better solution. Leaving bug open for now.
Committing to: bzr+ssh://dlawrence%40mozilla.com@bzr.mozilla.org/bmo/4.0
modified extensions/SecureMail/Extension.pm
Committed revision 8111.
dkl
Comment 16•14 years ago
|
||
Thanks David! Do you know when this will be deployed to bmo?
| Reporter | ||
Comment 17•14 years ago
|
||
It appears to be deployed now.
Comment 18•11 years ago
|
||
(In reply to David Lawrence [:dkl] from comment #14)
> Added workaround that puts the bug id in the subject text to see if this
> fixes the gmail threading issue for those affected.
>
> [Bug XXXXXX] (Secure bug XXXXXX updated)
>
> I admit this is not optimal and has redundant data and we will remove this
> once we have a better solution. Leaving bug open for now.
Sadly unless we can convince gmail to change their threading algorithm, I don't think there is a better solution.
Also since this bug, I added the product/component to the subject (bug 1027638) - which at least makes it a little more usable.
As such, I think we can just close this as fixed - and file new bugs for any other ideas (if any).
Assignee: nobody → dkl
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Updated•6 years ago
|
Component: Extensions: SecureMail → Extensions
You need to log in
before you can comment on or make changes to this bug.
Description
•