From: http://www.cse.unsw.edu.au/~willu/ Date: Fri, 25 Jul 2008 01:46:23 +0000 (-0400) Subject: Add notes about possible security issues with rename - these look to be already cover... X-Git-Tag: 2.55~37 X-Git-Url: http://git.tremily.us/?p=ikiwiki.git;a=commitdiff_plain;h=7a070c64fab372cb829261a989eb28fdd30d306e;ds=sidebyside Add notes about possible security issues with rename - these look to be already covered in the source, but I wanted to make sure they're listed in the docs too. --- diff --git a/doc/todo/Moving_Pages.mdwn b/doc/todo/Moving_Pages.mdwn index 61f2663e0..cf1ce89c6 100644 --- a/doc/todo/Moving_Pages.mdwn +++ b/doc/todo/Moving_Pages.mdwn @@ -205,3 +205,9 @@ Cases to consider: Update: Meh. It's certianly not ideal; if Bob tries to save the page he uploaded the attachment to, he'll get a message about it having been deleted/renamed, and he can try to figure out what to do... :-/ +* I don't know if this is a conflict, but it is an important case to consider; + you need to make sure that there are no security holes. You dont want + someone to be able to rename something to /etc/passwd. + I think it would be enough that you cannot rename to a location outside + of srcdir, you cannot rename to a location that you wouldn't be able + to edit because it is locked, and you cannot rename to an existing page.