With the changes in bug 752946 it is possible to create a new bug (either via RPC or URL hijacking) with a milestone that is inactive. This shouldn't be allowed.
I've request the blocking on this bug on the same basis as the bug that created the problem.
Attachment #713221 - Flags: review?(glob)
Comment on attachment 713221 [details] [diff] [review] v1 patch I think the problem you describe affects versions and components too. IMO, the right fix is to write: my $old_foo = blessed($invocant) ? $invocant->foo : ''; This way, the first part of if ($object->name ne $old_foo && !$object->is_active) will always be false for new bugs (a component, version or milestone cannot be '') and we will always call !$object->is_active. So please fix this issue for versions and components too.
Attachment #713221 - Flags: review?(glob) → review-
This is less problematic for new bugs, because the UI doesn't list inactive values. So unless you hack the URL directly, honest users are not affected by this issue. But I'm fine to take it for 4.2.5 anyway as the fix in bug 752946 is incomplete.
Severity: normal → minor
Depends on: 752946
See Also: 752946 →
Summary: It is possible to create a bug with a non active target milestone → It is possible to create a new bug with a non active target milestone, version or component
Comment on attachment 713735 [details] [diff] [review] v2 patch No need to write : '' on its own line. On checkin, it should be moved on the same line as foo ? bar. r=LpSolit
Attachment #713735 - Flags: review?(LpSolit) → review+
Committing to: bzr+ssh://email@example.com/bugzilla/trunk/ modified Bugzilla/Bug.pm Committed revision 8577. Committing to: bzr+ssh://firstname.lastname@example.org/bugzilla/4.4/ modified Bugzilla/Bug.pm Committed revision 8518. Committing to: bzr+ssh://email@example.com/bugzilla/4.2/ modified Bugzilla/Bug.pm Committed revision 8187.
Status: ASSIGNED → RESOLVED
Closed: 7 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.