Closed Bug 840824 Opened 12 years ago Closed 12 years ago

It is possible to create a new bug with a non active target milestone, version or component


(Bugzilla :: Creating/Changing Bugs, defect)

Not set



Bugzilla 4.2


(Reporter: mail, Assigned: mail)




(1 file, 1 obsolete file)

With the changes in bug 752946 it is possible to create a new bug (either via RPC or URL hijacking) with a milestone that is inactive. This shouldn't be allowed.
Flags: blocking4.4?
Flags: blocking4.2.5?
See Also: → 752946
Attached patch v1 patch (obsolete) — Splinter Review
I've request the blocking on this bug on the same basis as the bug that created the problem.
Attachment #713221 - Flags: review?(glob)
Comment on attachment 713221 [details] [diff] [review]
v1 patch

I think the problem you describe affects versions and components too. IMO, the right fix is to write:

my $old_foo = blessed($invocant) ? $invocant->foo : '';

This way, the first part of

  if ($object->name ne $old_foo && !$object->is_active)

will always be false for new bugs (a component, version or milestone cannot be '') and we will always call !$object->is_active.

So please fix this issue for versions and components too.
Attachment #713221 - Flags: review?(glob) → review-
This is less problematic for new bugs, because the UI doesn't list inactive values. So unless you hack the URL directly, honest users are not affected by this issue. But I'm fine to take it for 4.2.5 anyway as the fix in bug 752946 is incomplete.
Severity: normal → minor
Depends on: 752946
Flags: blocking4.4?
Flags: blocking4.4+
Flags: blocking4.2.5?
Flags: blocking4.2.5+
See Also: 752946
Summary: It is possible to create a bug with a non active target milestone → It is possible to create a new bug with a non active target milestone, version or component
Attached patch v2 patchSplinter Review
Attachment #713221 - Attachment is obsolete: true
Attachment #713735 - Flags: review?(LpSolit)
Comment on attachment 713735 [details] [diff] [review]
v2 patch

No need to write : '' on its own line. On checkin, it should be moved on the same line as foo ? bar. r=LpSolit
Attachment #713735 - Flags: review?(LpSolit) → review+
Flags: approval4.4+
Flags: approval4.2+
Flags: approval+
Committing to: bzr+ssh://
modified Bugzilla/
Committed revision 8577.

Committing to: bzr+ssh://
modified Bugzilla/
Committed revision 8518.

Committing to: bzr+ssh://
modified Bugzilla/
Committed revision 8187.
Closed: 12 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.


