private ppa 'technical details' incorrect for people who can see the archive but don't have an access token

Bug #860273 reported by Martin Pool
22
This bug affects 4 people
Affects Status Importance Assigned to Milestone
Launchpad itself
Triaged
Low
Unassigned

Bug Description

When I visit a private ppa page and unfold the "technical details" section, I see sources.list lines including my username and p3a token.

However, when ~stephaneee visits one, there are lines that point to private-ppa.l.n but that do not have a username or password. These lines look like they will work, but they of course will not.

I guess this is due to an edge case of someone being in ~admin (or ~registry?) therefore able to see the p3a, but not actually having an access token for it.

Probably it would be better to replace that section with a message saying if you generate a token, you will be able to see the sources.list lines.

(This looks like bug 404279 was fixed incompletely.)

Martin Pool (mbp)
summary: - private ppa 'technical details' incorrect for admins
+ private ppa 'technical details' incorrect for people who can see the
+ archive but don't have an access token
tags: added: ppa
Revision history for this message
Julian Edwards (julian-edwards) wrote :

This is a dupe, but I can't find the original right now.

Curtis Hovey (sinzui)
tags: added: privacy
removed: private
Revision history for this message
Scott Ritchie (scottritchie) wrote :
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.