BMO/new-security-group: Difference between revisions

From MozillaWiki
< BMO
Jump to navigation Jump to search
(Created page with "= Adding a new security group = These steps need to be implemented when adding a new "security" group to BMO: 1. Add code to extensions/BMO/lib/Data.pm that accomplish the fol...")
 
m (added Category:BMO using HotCat)
 
(7 intermediate revisions by 2 users not shown)
Line 1: Line 1:
= Adding a new security group =  
== Adding a new security group ==


These steps need to be implemented when adding a new "security" group to BMO:
=== Creating the group ===


1. Add code to extensions/BMO/lib/Data.pm that accomplish the following:
* Security groups are rarely granted explicitly into. Normally the groups membership is determined by inheritance from other groups.
  a. %group_to_cc_map: Add the email address to automatically CC when a bug is placed in the security group.
* Most security groups have a related "-team" group that is used for actually granting people into. For example, noone is in the 'client-services-security' group directly. There is a 'client-services-security-team' group which is a member of the 'client-services-security' group. The individual users are placed directly into the 'client-services-security-team' group when needed. Therefore they get access to the other group as well through inheritance. Only the 'client-services-security' group should be actually visible on the bug report.
  b. %always_fileable_group: Add the group as one that can always be filed into, whoever you are.
* If the group is to be used as the default security group for a product (ie. it will be used when the user checks "Many users could be harmed by this security problem: it should be kept hidden from the public until it is resolved"), it must be set to '''Shown/Shown'''.
  c. %product_sec_groups: Add the product to group mapping for the new security group.


2. Security groups rare can be bless directly into even admins. Normally the groups membership is determined by inheritance from other groups.
=== Code changes===
 
These steps need to be implemented by the admin when adding a new "security" group to BMO after the group has been created on BMO:
 
* Add code to extensions/BMO/lib/Data.pm that accomplish the following:
** If the group is to be used as the default security group for a product, add the group to <tt>%product_sec_groups</tt>
** If the requester wanted an automatic CC when a bug is placed into the group, update <tt>%group_to_cc_map</tt>
 
[[Category:BMO]]

Latest revision as of 03:45, 13 January 2015

Adding a new security group

Creating the group

  • Security groups are rarely granted explicitly into. Normally the groups membership is determined by inheritance from other groups.
  • Most security groups have a related "-team" group that is used for actually granting people into. For example, noone is in the 'client-services-security' group directly. There is a 'client-services-security-team' group which is a member of the 'client-services-security' group. The individual users are placed directly into the 'client-services-security-team' group when needed. Therefore they get access to the other group as well through inheritance. Only the 'client-services-security' group should be actually visible on the bug report.
  • If the group is to be used as the default security group for a product (ie. it will be used when the user checks "Many users could be harmed by this security problem: it should be kept hidden from the public until it is resolved"), it must be set to Shown/Shown.

Code changes

These steps need to be implemented by the admin when adding a new "security" group to BMO after the group has been created on BMO:

  • Add code to extensions/BMO/lib/Data.pm that accomplish the following:
    • If the group is to be used as the default security group for a product, add the group to %product_sec_groups
    • If the requester wanted an automatic CC when a bug is placed into the group, update %group_to_cc_map