Re: xml-rpc



On Fri, 2004-07-09 at 09:46 +0200, Daniel Egger wrote:
> On 09.07.2004, at 03:12, Luis Villa wrote:
> 
> > not... I'm real tempted to go ahead, throw it on bugzilla, and see what
> > happens.
> 
> > thoughts? plans? screams?
> 
> Which tools are utilizing XMLRPC to interface bugzilla?

bug-buddy will, and RH's bugtool already does.

> I hope it still requires authentication?

I assume so, since this is based on the RH patch, and RH is much more
paranoid about authentication than we are :) But I have not actually
verified this.

> Also I hope that it is *not* possible to get *any* bug
> information without authentication because this is a
> major possibility to harvest addresses for spammail
> with very little effort.

We're pretty much already screwed on this count. If we care, we need to
steal KDE's patch to obscure these.

> Having XMLRPC support for bugzilla is certainly tempting
> but I'd only do this iff
> a) there a real users
> b) this provides major benefits that cannot be had otherwise
> c) all security issues are cleared up

I haven't looked at (c) (I've just taken it for granted that RH has
investigated the issue) but (a) and (b) are definitely the case.

Luis




[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]