Closed
Bug 740830
Opened 13 years ago
Closed 13 years ago
Secreview: In App Payment - AppSecret revocation/replacement
Categories
(mozilla.org :: Security Assurance, task)
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: curtisk, Assigned: markg)
References
()
Details
(Whiteboard: [action Item])
what do app servers do in case of AppSecret compromise? need revocation/replacement mechanism (write up for MDN)
this bug blocks market rollout
Comment 1•13 years ago
|
||
Making this bug p1 for April 26th launch. Feel free to demote the bug if that's not the case.
Priority: -- → P1
![]() |
Reporter | |
Comment 3•13 years ago
|
||
Yes, per the security review this is a blocker for rolling out the marketplace.
Comment 4•13 years ago
|
||
Where is the plan/eta? next steps? Are you talking about blocking the final launch or an intermediate launch?
![]() |
Reporter | |
Comment 5•13 years ago
|
||
the plan or eta should be coming from Mark (assignee) and this would block final launch.
Assignee | ||
Comment 6•13 years ago
|
||
I do not have enough info on this to write it. Can someone give me some raw info to use for my MDN write-up on this?
Assignee | ||
Comment 7•13 years ago
|
||
I have added info on how to handle a compromised app secret to MDN here:
https://developer.mozilla.org/en/Apps/In-app_payments#section_5
I can't tell if this bug is docs only, or if it also requires code from someone else. So I did not change its status to RESOLVED.
![]() |
Reporter | |
Comment 8•13 years ago
|
||
CC :rforbes as he was the lead on this bug is not on this bug
Comment 9•13 years ago
|
||
There is a current process in place where app developers can revoke a compromised secret in a timely manner. Mark has documented this so I'm closing the bug. Take note that there will be an optimized UI flow for this in bug 738368 but that's just an enhancement.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
![]() |
Reporter | |
Updated•13 years ago
|
Summary: [Security Review][Action Item]In App Payment - AppSecret revocation/replacement → Secreview: In App Payment - AppSecret revocation/replacement
Whiteboard: [action Item]
You need to log in
before you can comment on or make changes to this bug.
Description
•