private ppa access granted to inactive persons

Bug #1006692 reported by Robert Collins
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
High
Colin Watson

Bug Description

generate-ppa-htaccess currently includes invalid persons (e.g. no current email, or marked inactive, or is a team) in the htpasswd file that is generated. This means that someone who previously had an LP account, with access to a private archive (e.g. commercial or OEM or whatnot), and deactivates their account will have effectively invisible access forever (because the UI and most API routines filter out invalid persons).

Related branches

Curtis Hovey (sinzui)
tags: added: merge-deactivate ppa privacy
Revision history for this message
Colin Watson (cjwatson) wrote :

I think the new WSGI authenticator still has this problem, although it should now be easier to fix since we won't need to schedule htpasswd updates when account statuses change.

Colin Watson (cjwatson)
Changed in launchpad:
status: Triaged → In Progress
assignee: nobody → Colin Watson (cjwatson)
Colin Watson (cjwatson)
Changed in launchpad:
status: In Progress → Fix Released
information type: Private Security → Public Security
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.