https://bugzilla.wikimedia.org/show_bug.cgi?id=48836

--- Comment #6 from Andre Klapper <[email protected]> ---
Admins have access to the Security product by default (as "admin" group
membership inherits membership in the "security" group), and people who are no
admins but members of the "security" group in Bugzilla have access to the
Security product anyway. So there are no people who gain this new right but
cannot access the Security product.

Members of the "admin" and "security" groups are automatically members of the
new "privatecomments" group, but people manually added to the "privatecomments"
group (none so far, and no plans to do so) do not automatically gain access to
tickets filed in the Security product.
In order to manually add people to the "privatecomments" group, a member of
either the "admin" or "editusers" group would be needed. And admins should be
trusted people anyway.


Does that sort out the raised concerns, or do I misunderstand something?

(And thanks for the quick comments here, really appreciated!)

-- 
You are receiving this mail because:
You are on the CC list for the bug.
_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to