Ticket #677 (closed defect: fixed)

Opened 2 years ago

Last modified 2 years ago

'Shutdown Gracefully' does not respect auth

Reported by: theuni Owned by:
Priority: blocker Milestone: 0.8.0
Version: 0.7.11 Keywords:
Cc:

Description

As per IRC conversation with djmitche:

When allowForce=True and auth is set, the 'Shutdown Gracefully' button on the buildslave page should respect the setting and be behind the auth. Otherwise users are able (and apparently very willing) to click it. This is very nasty as the expected behavior is that auth protects from unauthorized tampering.

Change History

comment:1 Changed 2 years ago by theuni

Now that I think about it, the 'Ping' functionality falls under the same logic in my opinion. Would be great to see it honor auth as well.

comment:2 Changed 2 years ago by dustin

  • Priority changed from major to blocker
  • Milestone changed from undecided to 0.8.0

comment:3 Changed 2 years ago by dustin

  • Status changed from new to closed
  • Resolution set to fixed

woo, all accomplished in #701.

Note: See TracTickets for help on using tickets.