Closed
Bug 45579
Opened 25 years ago
Closed 22 years ago
Params page should require a password to VIEW, not just update
Categories
(Webtools Graveyard :: Bonsai, defect, P3)
Webtools Graveyard
Bonsai
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: justdave, Assigned: tara)
References
()
Details
(Whiteboard: security)
Attachments
(2 files)
1.02 KB,
patch
|
Details | Diff | Splinter Review | |
1.06 KB,
patch
|
Details | Diff | Splinter Review |
Although it's nice that you have to enter a password in order to change Bonsai
parameters from the web, I think it would be better if you had to enter the
password in order to even SEE the parameters. The admin page isn't so bad,
because it's mostly commands to do stuff, and you have to have the password to
run them. But the editparams page linked to from admin is wide open. As
mentioned, you have to enter a password to update it, but since it contains your
database username and password in particular, it's probably not a good thing to
have out in the open.
I notice someone at mozilla.org was concerned about that, too, because they have
those two params blanked out on the parameters page, and they probably hardcoded
it in the files that used it.
I noticed this too. IMHO it should be at least noted in the documentation.
Severity: normal → major
QA Contact: matty → timeless
Whiteboard: security
Comment 2•22 years ago
|
||
In case anyone cares
Assignee | ||
Comment 3•22 years ago
|
||
I've been looking at this and I'd love to have Bugzilla-style authorization, but
that would entail creating a users/roles table which is probably overkill. Will
definitely update the docs, but will continue to try and come up with something
a little more elegant.
Status: NEW → ASSIGNED
Assignee | ||
Comment 4•22 years ago
|
||
Assignee | ||
Comment 5•22 years ago
|
||
Hrm, fixed the text slightly to make more sense (Bonsai doesn't really have a
concept of "log in") and checking this baby in...
Status: ASSIGNED → RESOLVED
Closed: 22 years ago
Resolution: --- → FIXED
Updated•9 years ago
|
Product: Webtools → Webtools Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•