launchpad-dev team mailing list archive
-
launchpad-dev team
-
Mailing list archive
-
Message #07453
Re: Changing Lp to not conflate public, private, and securty visibility
On Wed, 2011-06-22 at 13:33 +0100, Julian Edwards wrote:
> Are you going to differentiate at all between "knowledge of" and
> "access" in
> this feature?
We decided that we will not copy the double-secret-probation rule we
used with private teams. There are many places we cannot use private
teams because they would leak their names. There are other places were
we show <hidden team>.
The new rule will be you can now it exists, know its name, but you
cannot see inside the artefact. You may know it exists if the object you
have full or partial privilege to the private context. This enforced
though traversal like teams.
I expect some messy work with objects being pulled out of context. Teams
generated a lot of 403 until we fixed the callsites.
--
__Curtis C. Hovey_________
http://launchpad.net/
Attachment:
signature.asc
Description: This is a digitally signed message part
References