Page MenuHomePhabricator

Reclaim @security_team_bot
Closed, ResolvedPublic

Description

I think only Chase may have known the password for @security_team_bot... Is there a password? I'm not sure how it works.

Is there a password? What email address (if any) is assigned to it?

Can we get the password reset so we can add it ot the Security-Team shared password vault etc?

Event Timeline

Reedy created this task.Oct 19 2020, 4:34 PM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptOct 19 2020, 4:34 PM
Reedy renamed this task from Reclaim @secbot to Reclaim @security_team_bot.Oct 19 2020, 4:48 PM

There is no password. The only interaction is possible via the Conduit API token, hence it technically cannot be "claimed" I guess.
Phab admins can access the token via https://phabricator.wikimedia.org/settings/user/security_team_bot/page/apitokens/

The email address of a bot account isn't used. In this case it is the name of a previous colleague followed by +secteambot followed by @wikimedia.og [sic!].

Thanks.

Yeah, I'd realised I could get a token for it via https://phabricator.wikimedia.org/settings/user/security_team_bot/page/apitokens/

Is there any point changing the email of the account?

Is there any point changing the email of the account?

I don't think so - it can be invalid and whatever. See also https://www.mediawiki.org/wiki/Phabricator/Bots#Acquiring_a_bot

Is there any point changing the email of the account?

I don't think so - it can be invalid and whatever. See also https://www.mediawiki.org/wiki/Phabricator/Bots#Acquiring_a_bot

I'd suggest it might be worth at least blanking it, so that it doesn't confusingly point to a departed team mate. Or maybe updating it to one of Security-Team 's shared addresses like security-team@ or security-help@.

I don't think changing the email address is possible via the web UI (and as the address is not exposed anywhere I don't see which problem this would solve).

Reedy closed this task as Resolved.Mon, Oct 26, 3:07 PM
Reedy claimed this task.