Closed Bug 740830 Opened 13 years ago Closed 13 years ago

Secreview: In App Payment - AppSecret revocation/replacement

Categories

(mozilla.org :: Security Assurance, task)

x86
macOS
task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: curtisk, Assigned: markg)

References

()

Details

(Whiteboard: [action Item])

what do app servers do in case of AppSecret compromise? need revocation/replacement mechanism (write up for MDN) this bug blocks market rollout
Making this bug p1 for April 26th launch. Feel free to demote the bug if that's not the case.
Priority: -- → P1
What's the status of this bug? Does it still block?
Priority: P1 → --
Yes, per the security review this is a blocker for rolling out the marketplace.
Where is the plan/eta? next steps? Are you talking about blocking the final launch or an intermediate launch?
the plan or eta should be coming from Mark (assignee) and this would block final launch.
I do not have enough info on this to write it. Can someone give me some raw info to use for my MDN write-up on this?
I have added info on how to handle a compromised app secret to MDN here: https://developer.mozilla.org/en/Apps/In-app_payments#section_5 I can't tell if this bug is docs only, or if it also requires code from someone else. So I did not change its status to RESOLVED.
CC :rforbes as he was the lead on this bug is not on this bug
There is a current process in place where app developers can revoke a compromised secret in a timely manner. Mark has documented this so I'm closing the bug. Take note that there will be an optimized UI flow for this in bug 738368 but that's just an enhancement.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Summary: [Security Review][Action Item]In App Payment - AppSecret revocation/replacement → Secreview: In App Payment - AppSecret revocation/replacement
Whiteboard: [action Item]
You need to log in before you can comment on or make changes to this bug.