Describe what you need us to do: Investigate why I was able to set @shuff as admin to https://src.fedoraproject.org/rpms/lastpass-cli/ - @shuff is not in the packagers group, therefore it should not be possible
When is this no longer needed or useful? (YYYY/MM/DD)
When we do not use dist-git pagure anymore.
People might be added as admin to packages without being able to maintain them.
Metadata Update from @mizdebsk: - Issue tagged with: src.fp.o
How did you grant the access? Using the API? The web UI?
I guess via the web UI.
Metadata Update from @pingou: - Issue assigned to pingou
Ok, reading the code, this is a bug in pagure, looking into it some more
Fixed upstream in https://pagure.io/pagure/pull-request/3383
It'll be in the upcoming release, unless we want to hotfix it before. Thoughts?
When do you plan to release? I guess it does not need hotfixing given that their actions are limited anyhow. When the change is in we should do a review o make sure that all users are in the group, though.
Shall we keep this ticket open? Or is there anything we want to keep tracking here?
Metadata Update from @kevin: - Issue priority set to: Waiting on Assignee (was: Needs Review)
Metadata Update from @mizdebsk: - Issue close_status updated to: Fixed - Issue status updated to: Closed (was: Open)
Fixed Pagure is deployed and I've heard feedback from a user confirming the fix in production.
Log in to comment on this ticket.