Bug 1851434: guard secure_mail call for installs without SecureMail extension - #183
Open
topunix wants to merge 2 commits into
Open
Bug 1851434: guard secure_mail call for installs without SecureMail extension#183topunix wants to merge 2 commits into
topunix wants to merge 2 commits into
Conversation
assert_password_is_secure has been an empty stub since 8edd271 removed Data::Password::passwdqc, so no password strength check has run since. Restore the pre-passwdqc logic from e9adcde: a minimum length check plus the optional character class rule keyed off the existing password_complexity param. Add a password_check hook so a stricter policy can be supplied by an extension rather than by a core dependency. Remove the six passwdqc_* params, their checkers and their help text, along with t/903-passwdqc-conf.t, since nothing reads them. Update two test fixture passwords that did not satisfy the bmo complexity rule, which is enabled in the CI answers file and had been unenforced while the stub was empty.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bugzilla/Bug.pm calls $group->secure_mail unconditionally when a bug is
made public. That method only exists because SecureMail's Extension.pm
installs it into Bugzilla::Group at load time, and SecureMail ships
disabled, so any install without it dies with:
Can't locate object method "secure_mail" via package "Bugzilla::Group"
This surfaced in the webservice QA suite. The "groups: remove Master"
test died there, leaving the test bug group-restricted, which cascaded
into 198 failures across webservice_bug_update.t. Guarding the call
takes that file from 198 failures to zero (921 passing).
Six failures remain in webservice_user_create.t from an unrelated cause
(assert_password_is_secure is an empty stub), so the webservice job in
ci.yml stays commented out for now.