Log creates publically readable private conversation files

Bug #567576 reported by Stefano Rivera
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ibid
Fix Released
High
Stefano Rivera

Bug Description

When the bot speaks first, the logfile it creates is publically readable forever.

There seem to be other situations where this happens (NOTICEs for a start).

Related branches

Revision history for this message
Max Rabkin (max-rabkin) wrote :

I'm not even convinced that logs of public channels should be public (and now that the bot accepts invitations, it can be invited to private chat rooms on IRC, and AIUI this was always the case on SILC). There are chat rooms where one expects that, although anybody can join, one can always see who is reading (and shut up if necessary).

Revision history for this message
marcog (marco-gallotta) wrote :

> I'm not even convinced that logs of public channels should be public

+1

Revision history for this message
Max Rabkin (max-rabkin) wrote :

I propose that log visibility should be controlled by config on per channel basis, with private as the default.

Changed in ibid:
importance: Low → High
Changed in ibid:
assignee: nobody → Stefano Rivera (stefanor)
status: Triaged → In Progress
Changed in ibid:
status: In Progress → Fix Committed
Max Rabkin (max-rabkin)
Changed in ibid:
status: Fix Committed → Fix Released
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.