Closed mikecirioli closed 6 months ago
@jetersen @rsandell @MarkEWaite Could i kindly get a review of this PR please?
@mikecirioli can you describe the interactive testing that you performed to confirm that it is behaving as expected? The "Testing done" section is the place where that should be described.
@MarkEWaite I've updated the description to include the testing done, let me know if you need anything else
@jetersen can i get an additional review when you have the time?
https://issues.jenkins.io/browse/JENKINS-73061
Based on JEP-223, this operation does not allow users to escalate permissions and it's not related to security, so it qualifies to be accessible with the Overall/Manage permission.
Testing done
file://
uri's were properly caughtOverall/Manage
can configure the feature. Also verified that no information was leaked when attempting to configure dodgy urls likefile://etc/passwd
, and secrets inJENKINS_HOME