Skip to content

Bug 1851434: guard secure_mail call for installs without SecureMail extension - #183

Open
topunix wants to merge 2 commits into
bugzilla:mainfrom
topunix:bug-1851434
Open

Bug 1851434: guard secure_mail call for installs without SecureMail extension#183
topunix wants to merge 2 commits into
bugzilla:mainfrom
topunix:bug-1851434

Conversation

@topunix

@topunix topunix commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Bugzilla/Bug.pm calls $group->secure_mail unconditionally when a bug is
made public. That method only exists because SecureMail's Extension.pm
installs it into Bugzilla::Group at load time, and SecureMail ships
disabled, so any install without it dies with:

Can't locate object method "secure_mail" via package "Bugzilla::Group"

This surfaced in the webservice QA suite. The "groups: remove Master"
test died there, leaving the test bug group-restricted, which cascaded
into 198 failures across webservice_bug_update.t. Guarding the call
takes that file from 198 failures to zero (921 passing).

Six failures remain in webservice_user_create.t from an unrelated cause
(assert_password_is_secure is an empty stub), so the webservice job in
ci.yml stays commented out for now.

assert_password_is_secure has been an empty stub since 8edd271
removed Data::Password::passwdqc, so no password strength check has
run since. Restore the pre-passwdqc logic from e9adcde: a minimum
length check plus the optional character class rule keyed off the
existing password_complexity param.

Add a password_check hook so a stricter policy can be supplied by an
extension rather than by a core dependency.

Remove the six passwdqc_* params, their checkers and their help text,
along with t/903-passwdqc-conf.t, since nothing reads them.

Update two test fixture passwords that did not satisfy the bmo
complexity rule, which is enabled in the CI answers file and had been
unenforced while the stub was empty.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant