Re: Summary of BTS evaluations

Re: Summary of BTS evaluations

To: John Goerzen <jgoerzen@xxxxxxxxxxxx>
Cc: offlineimap@xxxxxxxxxxxx
Subject: Re: Summary of BTS evaluations
From: Martijn Pieters <mj@xxxxxxxx>
Date: Fri, 19 Jul 2002 11:39:15 -0400

On Fri, Jul 19, 2002 at 10:19:21AM -0500, John Goerzen wrote:
> Pros:
>  * Written in Python and has a Python API
>  * Quick install for a default configuration
>  * Looks reasonably secure
>  * Has a nice e-mail interface built-in
>  * Nice way of parsing e-mail attachments and making them into bug
>    attachments
> Cons:
>  * Making changes to the config requires editing cryptic text files or even
>    deleting all info in the database and restarting
>  * Not a lot of flexibility in the security part.  Either people can
>    do everything or they can do nothing.

The way I see it is that if you allow email to change bug status, security
is moot anyway unless you require GPG signatures. I can *easily* forge email
messages that pretend to come from someone else without signatures.

Also, I understand the auditor/detector mechanism allows for some
flexibility here.

>  * Interface is kinda ugly

But the templates are flexible; just redefine the colours, right?

Martijn Pieters
| Software Engineer  mailto:mj@xxxxxxxx
| Zope Corporation
| Creators of Zope

