Page MenuHomePhabricator

Grant access to OIT-LDAP Diffusion repo to contractor Danielattevelt
Closed, ResolvedPublic

Description

Hello-

The Security-Team has a contractor (@Danielattevelt) who will be performing a security review of the OIT-LDAP-Tools WMF-internal application. We have already verified their identity and granted them access to the related task: T155537. The relevant Diffusion repository is currently protected via the acl*security_team policy. I'd prefer to grant access to the repository to the specific, aforementioned user, but I'm not sure that's possible. If it's not possible, would the next best approach be to create a new Phabricator group where the specific, aforementioned user was a member and temporarily add that to the repository's access policy? Thanks.

Event Timeline

sbassett moved this task from Incoming to In Progress on the Security-Team board.
sbassett updated the task description. (Show Details)
Aklapper renamed this task from Grant access to OIT-LDAP Diffusion repo to contractor to Grant access to OIT-LDAP Diffusion repo to contractor Danielattevelt.Jul 22 2021, 12:06 PM

Simply adding the user to the policy on Restricted Repository should be fine. I'll take care of it if I can access that ACL.

Ok I added @Danielattevelt to the visibility custom policy via the rWOLT repository's policy management page.

sbassett moved this task from In Progress to Our Part Is Done on the Security-Team board.