New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 880939 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Last visit > 30 days ago
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

Security: Able to add myself as reviewer. Is this expected?

Reported by aj.jaswa...@gmail.com, Sep 5

Issue description

I am seeing options to do "VERIFIED+1", "CQ DRY RUN" etc.,
Components: Infra>Codereview>Gerrit
Owner: no...@chromium.org
Hi Nodir, can you please assign an owner and confirm the issue?
Cc: jpar...@google.com no...@chromium.org
Owner: jparent@chromium.org
Cc: jeffcarp@chromium.org
https://chromium-review.googlesource.com/changes/1113917/revisions/28/cherrypick seems to be working with sample payload '{"message":"temp","destination":"A_VALID_BRANCH","keep_reviewers":false}'
you can also see them in
https://chromium.googlesource.com/chromiumos/platform2/+refs
this is WAI. Entire chromium.googlesource.com is public.
Screenshot of https://chromium-review.googlesource.com/c/chromiumos/platform2/+/1178239
Screen Shot 2018-09-06 at 1.30.05 AM.png
353 KB View Download
Only concerning thing is the options for revert and reland. I've not attempted to use them.
note that these buttons won't let arbitrary users to actually revert or reland a CL. They would create a new CL scheduled for landing, but it wouldn't be landed without approvals of authority. It is spam, though.
Is there any security bug here? Or is there just work to be done on spam prevention?
Cool. Got it. Thanks.
Project Member

Comment 13 by sheriffbot@chromium.org, Sep 6

Status: Assigned (was: Unconfirmed)
i don't see a security bug
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Okay, removing the labels, but re:comment 10, you mentioned it is spam. Is there anything to be done for that?
Labels: Pri-2
Setting defect without priority to Pri-2.

Sign in to add a comment