#736 [BUG] SPONSOR can give "SPONSOR" status to any new FAS account in packager group
Closed: Fixed None Opened 15 years ago by paragn.

Hi,
I found BUG that I can upgrade anyone directly from no status to SPONSOR status. So even user with SPONSOR status can upgrade new FAS users to SPONSOR instead "user" status.

Is that really bug or some kind of testing going on?

Regards,
Parag.


What group are you talking about and are you a sponsor of that group? Sponsors can make sponsors of other people.

Replying to [comment:1 mmcgrath]:

What group are you talking about and are you a sponsor of that group? Sponsors can make sponsors of other people.
Cool. I was not knowing this thing. When I was made SPONSOR in packager(then cvsextras) group, FESCO voted on my name and I think people with Admin status did upgraded me from "user" to "SPONSOR".
If packager group is now open then I think nowadays we don't require FESCO to vote on whom to make SPONSOR in packager group. So I can make now anyone and many more SPONSORS in packager without FESCO permission.
And yes I am SPONSOR status in packager cvs group.

If I am wrong then please correct me.

Regards,
Parag.

oops sorry I saw my reply got mixed with your question. sorry.

No worries, that is the correct behavior

Users: Can't upgrade or downgrade anyone

Sponsors: Can sponsor/upgrade users (even if they're not approved yet) but not downgrade admins or other sponsors

Admins: Can upgrade or downgrade anyone.

Note: I think sponsors can downgrade sponsors - if that's a bug/not intended, then it's a simple fix in FAS.

Just want to add note here. FAS accounts with status "sponsor" can upgrade existing and new peoples in FAS directly to "sponsor" status with current FAS implementation.
I have already made a lot of noise on IRC on #fedora-admin as well as in PM with fedora-infra team members.

I just thought if FESCo asks nominations and approves someone in FAS from "user" to "sponsor" status then same should be applied in FAS preventing non-FESCo members to upgrade "user" to "sponsor".

If infra team still sees I am making unnecessary request and noise here then feel free not to pay attention to my request.

Thanks to all infra team for reading reported problem here.

I'm sorry, I forgot to update the ticket - the authorizations have been fixed in FAS in git, but we haven't done a new release yet.

Thank you very much for reporting this - it was an unexpected change from the original FAS behavior.

Login to comment on this ticket.

Metadata