You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently the change submission path via the Buildbot webhook API is not properly authenticated, and this could be an abusable flaw. Once Buildbot is moved to altair and modernized, add a new webhook parser plugin which supports some kind of HMAC signature, or at the very least something like HTTP basic auth.
(I think we might actually be able to do HTTP basic auth already as a stopgap, but haven't tried.)
The text was updated successfully, but these errors were encountered:
Currently the change submission path via the Buildbot webhook API is not properly authenticated, and this could be an abusable flaw. Once Buildbot is moved to altair and modernized, add a new webhook parser plugin which supports some kind of HMAC signature, or at the very least something like HTTP basic auth.
(I think we might actually be able to do HTTP basic auth already as a stopgap, but haven't tried.)
The text was updated successfully, but these errors were encountered: