Comment 19 for bug 1677723

Revision history for this message
Lance Bragstad (lbragstad) wrote : Re: federated user gets wrong role (CVE-2017-2673)

Based on comment #18, we need to re-spin the proposed patch in comment #6 to make it test a mapping that doesn't enable auto-provisioning. We should certainly keep the auto-provisioning test coverage, but we should add a test case that shows this can be done with mappings that don't rely on that feature.

Jeremy and Tristan,

Do we need to extend the proposed disclosure date if the communication needs to be amended?