Page MenuHomePhabricator

Remove 'shell user' right on wikitech
Open, MediumPublic

Description

Wikitech has a 'shell user' user right. This used to be checked before permitting logins; I don't know if it still is, or how it's checked if it is.

As we move our developer account workflow away from wikitech, having logins require a particular bit on a particular wiki seems wrong. If bit right is already ignored, then we should remove it from wikitech; if it's still used we should replace it or ignore it and rely on keystone roles exclusively.

Event Timeline

Andrew created this task.Jun 5 2018, 1:44 PM

AFAIK this used be a way to disable abusive accounts (by removing this right they could no longer log in, which normal blocking on wikitech didn't do iirc). Did keystone roles take that functionality over? Even if rarely used, there should be a easy way to disable abusive accounts on wmcs.

Vvjjkkii renamed this task from Review (and remove?) use of 'shell user' right on wikitech to xlbaaaaaaa.Jul 1 2018, 1:06 AM
Vvjjkkii triaged this task as High priority.
Vvjjkkii updated the task description. (Show Details)
TerraCodes renamed this task from xlbaaaaaaa to Review (and remove?) use of 'shell user' right on wikitech.Jul 1 2018, 12:55 PM
TerraCodes raised the priority of this task from High to Needs Triage.
TerraCodes updated the task description. (Show Details)
Meno25 added a subscriber: Meno25.May 31 2019, 4:29 PM

AFAIK this used be a way to disable abusive accounts (by removing this right they could no longer log in, which normal blocking on wikitech didn't do iirc). Did keystone roles take that functionality over? Even if rarely used, there should be a easy way to disable abusive accounts on wmcs.

Blocking an account on Wikitech disables the associated Developer account including preventing new ssh sessions to Cloud VPS projects. The checks for this are in ssh-key-ldap-lookup.py in ops/puppet.

bd808 renamed this task from Review (and remove?) use of 'shell user' right on wikitech to Remove 'shell user' right on wikitech.Nov 10 2019, 11:43 PM
bd808 triaged this task as Medium priority.
bd808 moved this task from Backlog to Config on the wikitech.wikimedia.org board.Nov 11 2019, 12:29 AM