From 965afd875cd168713e9351d3c4c992c31f0bea0a Mon Sep 17 00:00:00 2001 From: joey Date: Sat, 11 Mar 2006 05:41:25 +0000 Subject: [PATCH] up --- doc/bugs.mdwn | 2 ++ doc/security.mdwn | 8 +++++++- doc/todo.mdwn | 7 ++----- ikiwiki | 2 ++ 4 files changed, 13 insertions(+), 6 deletions(-) diff --git a/doc/bugs.mdwn b/doc/bugs.mdwn index b1332fae5..45b6dd824 100644 --- a/doc/bugs.mdwn +++ b/doc/bugs.mdwn @@ -10,3 +10,5 @@ "Host key verification failed." I think that the setuid isn't fully taking; it should be running as me, but commit log shows www-data. So maybe it has the wrong username? +* Can't put the source in a directory named .source; the page finder skips + that due to too broad exclusion of any dotfile in a path. diff --git a/doc/security.mdwn b/doc/security.mdwn index 7b056fd6c..b72621111 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -74,6 +74,12 @@ Even with locking, if an attacker has local write access to the checkout, they could still fool ikiwiki using similar races. So it's best if only one person can ever write to the checkout that ikiwiki compiles the moo from. +## webserver symlink attacks + +If someone checks in a symlink to /etc/passwd, ikiwiki would publish that. +To aoid this, ikiwiki will need to avoid reading files that are symlinks. +TODO and note discussion of races above. + ## cgi security When ikiwiki runs as a cgi to edit a page, it is passed the name of the @@ -82,4 +88,4 @@ editing of ../../../foo, or editing of files that are not part of the wiki, such as subversion dotfiles. This is done by sanitising the filename removing unallowed characters, then making sure it doesn't start with "/" or contain ".." or "/.svn/". Annoyingly ad-hoc, this kind of code is where -security holes breed. +security holes breed. It needs a test suite at the very least. diff --git a/doc/todo.mdwn b/doc/todo.mdwn index ef3600d43..c3b26ef7b 100644 --- a/doc/todo.mdwn +++ b/doc/todo.mdwn @@ -6,12 +6,9 @@ * No support for web user tracking/login yet. * Doesn't svn commit yet. -## [[RecentChanges]] +## recentchanges -This will need to be another cgi script, that grubs through the -[[Subversion]] logs. - -This should support RSS for notification of new and changed pages. +Should support RSS for notification of new and changed pages. ## page history diff --git a/ikiwiki b/ikiwiki index f533cd096..e59051860 100755 --- a/ikiwiki +++ b/ikiwiki @@ -701,6 +701,7 @@ sub cgi () { print $q->header, $q->start_html("Creating $page"), $q->start_h1("$wikiname/ Creating $page"), + $q->end_hi, $q->start_form(-action => $action), $q->hidden('do'), "Select page location:", @@ -728,6 +729,7 @@ sub cgi () { print $q->header, $q->start_html("Editing $page"), $q->h1("$wikiname/ Editing $page"), + $q->end_hi, $q->start_form(-action => $action), $q->hidden('do'), $q->hidden('page'), -- 2.26.2