[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Savannah-hackers] serious bug in membership management
From: |
Yoshinori K. Okuji |
Subject: |
[Savannah-hackers] serious bug in membership management |
Date: |
Sun, 11 Jan 2004 10:15:19 +0100 |
User-agent: |
KMail/1.5 |
Hello,
There should be a serious bug in the membership management in Savannah.
To make things specific, I describe what happened in real life.
I'm the official maintainer of GNU GRUB, and it is hosted on
savannah.gnu.org. Some days ago, a contributor (Rick van Rein) was
misinterpretting a documentation in GNU GRUB, so he requested a
subscription to the membership of GNU GRUB via the Savannah interface,
just to submit a bug report. This was not a big problem, but he could
(actually he did) commit his patch to the CVS himself, and even
modified some fields of his own bug report in the bug tracker, which
are supposed to be modified only by administrators! Note that I didn't
accept his membership, as his request was just a mistake and I didn't
want to allow him to modify the CVS repository.
This bug can make all projects quite unsecure, IMHO. I wish this will be
fixed as soon as possible.
Thanks,
Okuji
- [Savannah-hackers] serious bug in membership management,
Yoshinori K. Okuji <=