Skip to content

Bug 2034032#2623

Merged
dklawren merged 2 commits into
masterfrom
2034032
May 20, 2026
Merged

Bug 2034032#2623
dklawren merged 2 commits into
masterfrom
2034032

Conversation

@dklawren
Copy link
Copy Markdown
Collaborator

r+ carried over from private pull request

Copilot AI review requested due to automatic review settings May 20, 2026 15:42
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens flag-notification email delivery to avoid leaking restricted bug information by ensuring the requestee/setter addressee is only emailed if they are permitted to see the bug and (when applicable) the private attachment.

Changes:

  • Add authorization checks for the flag notification “addressee” (bug visibility + private-attachment insider check) before adding them to recipients.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread Bugzilla/Flag.pm
@dklawren dklawren merged commit f6851bb into master May 20, 2026
8 checks passed
@dklawren dklawren deleted the 2034032 branch May 20, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants