Re: [SVN-MIGRATION] Fwd: Nearly 1000 authors to php.net
| From: | Richard Quadling | Date: | Mon, 10 Aug 2009 10:04:13 +0000 |
| Subject: | Re: [SVN-MIGRATION] Fwd: Nearly 1000 authors to php.net | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | svn.migration |
| Request: | Send a blank email to svn-migration+get-571@lists.php.net to get a copy of this message | ||
2009/8/9 Rasmus Lerdorf <rasmus@lerdorf.com>:
> Hannes Magnusson wrote:
>> On Sat, Aug 8, 2009 at 22:09, Rasmus Lerdorf<rasmus@lerdorf.com> wrote:
>>> Hannes Magnusson wrote:
>>>> On Sat, Aug 8, 2009 at 16:30, Rasmus Lerdorf<rasmus@lerdorf.com> wrote:
>>>>> Hannes Magnusson wrote:
>>>>>> On Sat, Aug 8, 2009 at 00:36, Gwynne Raskind<gwynne@darkrainfall.org>
>>>>>> wrote:
>>>>>>>> There are 343 users in global_avail which have never committed and
>>>>>>>> 271
>>>>>>>> authors not present in global_avail.
>>>>>> Some of those 271 are probably listed in the pear file.
>>>>>>
>>>>>> As people need to "verify" their accounts to get access to SVN we
>>>>>> can
>>>>>> quite easily see who use their accounts and who don't.
>>>>>> Then in 6months or so, kill off any unverified accounts...
>>>>> Keep in mind that we use it as our general auth mechanism, so there are
>>>>> people who have accounts who do not need svn access, but do need to be
>>>>> able to log in to edit notes, for example.
>>>> Meaning you want to split the database into "needs svn" and "needs
>>>> other stuff"?
>>>> Guess we could disable svn access, but keep the account, for anyone
>>>> who hasn't committed anything in couple of years.
>>> I see no real benefit to deleting accounts. What problem does it solve?
>>
>> Other then totally random people who do not work on the project being
>> able to retrieve MAGIC_COOKIE, and being able inject malicious code at
>> will?
>> Nothing really. The account approval process has been very strict over
>> the years and only trusted persons have access to important things...
>
> There is a difference between having an account and having SVN access.
> If people can commit malicious code at-will without being listed in the
> avail file, that is what we need to fix.
>
>
After including the pear_avail data, the totals are ...
406 users out of 1,283 users in global_avail or pear_avail have never commited.
79 authors out of the 956 authors are no longer present in
global_avail or pear_avail.
10 authors out of the 956 authors have access to all areas.
So, whilst getting to 1000 authors, nearly a third of users (31%) who
have permission to commit have never committed (as defined as being an
author to a commit).
Regards,
Richard.
P.S. I have a log file of all the names if anyone is interested. Too
big for the list (30,000 characters max).
--
-----
Richard Quadling
Zend Certified Engineer : http://zend.com/zce.php?c=ZEND002498&r=213474731
"Standing on the shoulders of some very clever giants!"
ZOPA : http://uk.zopa.com/member/RQuadling