Comment 21 for bug 434733

Revision history for this message
Curtis Hovey (sinzui) wrote :

We have a new pattern that might be employed to close this bug. Lp can show users the identifying info to users with limited view. Instead of showing a 404, Lp could show the bug title, project displayname and icon, with a message explaining that the rest of the information is not shared with the user. bug reporters, or affected users would be granted limited view. I think we need to discuss the rules for showing bug titles. Most private bugs have titles made by apport, but some are made by humans. I think these are generally safe to show. They are not disclosing user data. Security bugs probably do have meaningful titles, but I also image that the duplicate bug also has a meaningful title and the user knows it is a security issue...I doubt letting the user see the master bug title compromises data. We may not want to permit bugs to be duplicates of proprietary bugs, at least not until bug linking/relationships is complete.