James Carlson wrote:
> I've looked, and I don't see anything like that in the user interface.
> Perhaps I haven't looked in the right places, though, or maybe it's
> just that our version is too old.  I don't see anything related to
> "security."

When Alan writes that it isn't set up, he means it isn't set up.

Basically in order to mark a bug as confidential/security, there needs
to be such a group, and generally the person who wants to mark a bug
as confidential/security needs to be in the group.

Once the group is established, assigned to products, and you're a
member, you will see additional checkboxes in the bug.

> The sort of feature we need is the ability for the person filing the
> bug or anyone editing it to set a flag indicating that the bug has
> "security implications" and thus must be handled carefully.

https://bugzilla.mozilla.org/enter_bug.cgi?product=Core

Product:        [Core]  Reporter:       timel...@bemail.org
Component:      [.........|v]   
Component Description
[ Select a component to read its description. ]
Version:        [.........|v]   Severity:       [.........|v]
Platform:       [.........|v]
OS:     [.........|v]
Target Milestone:               [.........|v]
(        We've made a guess at your operating system and platform. Please
check them and make any corrections if necessary.)

Initial State:                  [.........|v]
Flags:
        wanted-next     [.........|v]
        blocking1.9.2   [.........|v]
        wanted1.9.2     [.........|v]
        blocking1.9.1   [.........|v]
        wanted1.9.1     [.........|v]
        blocking1.9.0.7 [.........|v]
        blocking1.9.0.8 [.........|v]
        wanted1.9.0.x   [.........|v]
        wanted-fennec1.0        [.........|v]
        blocking1.8.1.next      [.........|v]
        wanted1.8.1.x   [.........|v]
        blocking1.8.0.next      [.........|v]
        wanted1.8.0.x   [.........|v]
        in-litmus       [.........|v]
        in-testsuite    [.........|v]
Assign To:      [.........]
QA Contact:     [.........]
CC:     [.........]
Default CC:     [.........]

Alias:  [.........]
URL:    [.........]
Summary:        [.........]
Description:     [.........]
            [ ]  Initial Description is Private
Attachment:     [.........] [Browse]

Keywords:       [.........] (optional)
Depends on:     [.........]
Blocks: [.........]
        [ ] This is a security problem that should be kept confidential
until addressed (security policy).


Only users in all of the selected groups can view this bug:
(Leave all boxes unchecked to make this a public bug.)

      [ ] Security-Sensitive Core Bug

The "This is a security problem" part is a customization which someone
would implement. The Security-Sensitive Core Bug thing is because I'm
in a group 'Security-Sensitive Core' or something like that, a group
like this would have to be created (and will be, and is easy to do,
but well, it's on someone's todo list).
_______________________________________________
tools-discuss mailing list
tools-discuss@opensolaris.org

Reply via email to