Locked Files
Kelly Thomas
kthomas at siu.edu
Sat May 13 14:23:28 CDT 2006
ok, I understand what you are saying, but if the manila server knows
to lock everything in
http://server.com/betatest
...wouldn't it be a "simple" matter to have the server also lock
everything in
http://server.com/manila/gems/betatest at the same time?
I'm not running apache or anything else... I'd expect if I was, this
upload feature might very well allow access. I'd always assumed that
files/gems were restricted with the rest of the site as it's not
clear that those are excluded from the editors only lock."
I think this "security hole" is now a feature request. :-)
Thanks!
/kt
> From: Lawrence Lee <lawrence at userland.com>
> Date: May 12, 2006 1:20:29 PM CDT
> To: Manila-Users at userland.com
> Subject: RE: Locked Files
> Reply-To: Manila-Users at userland.com
>
>
> Files/gems currently aren't included in the Editors Only access
> restrictions. It's the same if you are using Manila to serve the
> files or an
> external static server like Ryan mentioned.
>
> Lawrence Lee
> UserLand Software
> www.userland.com
>
>
> -----Original Message-----
> From: manila-users-bounces at userland.com
> [mailto:manila-users-bounces at userland.com] On Behalf Of Kelly Thomas
> Sent: May 12, 2006 10:47 AM
> To: manila-users at userland.com
> Subject: Locked Files
>
> If I have a site and it's locked down via "Editors Only"
> http://newshound.de.siu.edu/betatest
>
> Is it normal that FILES belonging to that sire can be access by
> noneditors?
> http://newshound.de.siu.edu/manila/gems/betatest/TestDoc.pdf
>
> Did I miss something?
> Is there something I need to do differently?
>
> Thanks!
> /kelly
>
More information about the Manila-Users
mailing list