Closed Bug 925835 Opened 11 years ago Closed 11 years ago

Lock down developer tools for shared accounts

Categories

(Marketplace Graveyard :: Payments/Refunds, defect, P3)

x86
macOS
defect

Tracking

(Not tracked)

RESOLVED WORKSFORME
2013-10-28

People

(Reporter: andy+bugzilla, Assigned: andy+bugzilla)

Details

(Whiteboard: [ux-wanted][qa-])

If a developer links to a shared account, they should not be able to on the following screen:

http://cl.ly/image/0B2J0c0r0q3S

Accept the terms, delete or access the bango portal. Obviously the back end views need locking down appropriately as well.
Users who don’t create payment account might not be able to delete or modify it, but they should be able to access the portal and view information, right?
Who will have access to delete/modify the shared account?
Apps that use a shared account should not be to access the bango portal. That would contain information from all the apps that use the account.

The user who created the shared account will be able to delete or modify it.
Priority: -- → P3
Assignee: nobody → amckay
Target Milestone: --- → 2013-10-28
I don't think there's anything to do here, the appropriate calls check the right permissions. Most of the code to land using a shared account is in bug 925834.
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → WORKSFORME
Whiteboard: [ux-wanted] → [ux-wanted][qa-]
You need to log in before you can comment on or make changes to this bug.