Project can join a project group without group owner's permission
Bug #58297 reported by
Matthew Paul Thomas
This bug affects 4 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Launchpad itself |
Triaged
|
Low
|
Unassigned |
Bug Description
Anyone can register a project in Launchpad, and make it part of someone else's project group without approval from the owner(s) of that group. This can mislead people about the legitimacy of the project.
For example, the "Costato" project was able to join the Launchpad project group without approval from the Launchpad developers.
One way to fix this would be to require the project group owner's permission before adding any project.
This might be made an option for project groups.
description: | updated |
Changed in launchpad: | |
importance: | Untriaged → Low |
status: | Unconfirmed → Confirmed |
description: | updated |
Changed in launchpad-registry: | |
importance: | Low → Wishlist |
status: | Confirmed → Triaged |
tags: | added: oem-services |
Changed in launchpad-registry: | |
milestone: | none → series-future |
assignee: | Curtis Hovey (sinzui) → nobody |
tags: |
added: disclosure removed: registry |
tags: | added: hardening |
tags: |
added: private-projects removed: disclosure |
tags: | added: projectgroups |
no longer affects: | ubuntu |
To post a comment you must log in.
I'm going to investigate the overlap between ownership and member projects to see if it is viable to switch from a text field to a vocabulary to restrict the field to only project-groups that the user is an owner of.