15.4 Planning for Manage::Authentication and Authorization
15.4 Milestone: 2022-08-18 to 2022-09-17
Boards
- Build Board (%15.4 milestone issues to be built)
- Workflow Board (%15.4 issues in their current workflow states)
- Cross-Functional Prioritization Board
Capacity
Preliminary capacity - There is very little time off scheduled so far so I expect this to change
| Team | Weight |
|---|---|
| frontend | 7w |
| backend | 35w |
Capacity Goals
60% typefeature 10% typemaintenance 30% typebug
Objectives & Themes
- FedRAMP Required Items
- Fix open security bugvulnerability
- FY23:ROADMAP work (Custom Roles, Enterprise Users) - These have the direction label applied
- typemaintenance and typebug work
Security Issue Summary
If no security bugvulnerability roll over from %15.3, we will have 2 security issues for %15.4 which is within our expectations (~4 security issues per milestone). We are also done with past-SLO security issues
Product prioritized typefeature list
- New feature work - FY23:ROADMAP items, direction items
-
Main Themes: Customizable Roles, Domain Verification/Enterprise Users, FIPS follow up
-
See Feature Board. Items are stack ranked.
Quality prioritized typebug list
- https://gitlab.com/gitlab-org/gitlab/-/issues/368830+ (W? priority2 severity2 security bugvulnerability )
- https://gitlab.com/gitlab-org/gitlab/-/issues/368416+ (W? priority3 severity3 security bugvulnerability )
- Automatic Logouts Are Too Frequent (gitlab-org/gitlab#121569 - closed) ( W? priority2 severity2 SUSImpacting customer )
- Error when removing user's SCIM ID via API (gitlab-org/gitlab#368031 - closed) (W? priority2 severity2 customer )
- Cannot access Admin/credentials Project Access ... (gitlab-org/gitlab#354489 - closed) (W2 priority2 severity2 customer )
- Group owner cannot remove their group from a pr... (gitlab-org/gitlab#251137 - closed) ( W3 priority2 severity2 SUSImpacting customer )
- A group access token cannot be used to create a... (gitlab-org/gitlab#365904 - closed) (W? priority2 severity2 customer )
- Self-managed SAML - bypass 2 factor authenticat... (gitlab-org/gitlab#196131 - closed) (? priority4 severity4 SUSImpacting ) - Stretch?
- Expensive query on /admin/applications times ou... (gitlab-org/gitlab#366936 - closed) (W1 priority3 severity3 SUSImpacting ) - Stretch?
For consideration
- Show SAML status badge for members in subgroups... (gitlab-org/gitlab#11870 - closed) (W3 priority3 severity3 SUSImpacting customer )
- GitLab.com Group access tokens continue working... (gitlab-org/gitlab#367740 - closed) (W? priority3 severity2 security customer )
Slipped %15.3
- User approval: Rejecting reloads page (gitlab-org/gitlab#342845 - closed) (W2 severity4 priority2 SUSImpacting )
- Incorrect password while enabling 2FA does not ... (gitlab-org/gitlab#346494 - closed) (W2 priority2 severity2 customer)
- Overriding LDAP permissions no longer possible (gitlab-org/gitlab#337539 - closed) (W3 priority2 severity2)
Engineering prioritized typemaintenance list
See maintenance list, they are prioritized from top to bottom.
Release Post Items
Other
Edited by Hannah Sutor