Add comment about this issue
parent
827bd1d990
commit
f6127eb9fa
|
@ -17,4 +17,4 @@ This makes it a little hard to specify which specific binaries should be used, e
|
||||||
> checking happy, but as taint checking is disabled anyway, I have removed
|
> checking happy, but as taint checking is disabled anyway, I have removed
|
||||||
> that. [[done]] --[[Joey]]
|
> that. [[done]] --[[Joey]]
|
||||||
|
|
||||||
Question: Do ikiwiki.cgi and the RCS post-commit script sanitize the $PATH separately from bin/ikiwiki? If not, then bin/ikiwiki is probably right to sanitize the $PATH; otherwise you've created a security hole with access to the account that ikiwiki is SUID to. It'd be nice if /opt/local/bin were earlier in the $PATH, but that can be changed (as noted) in the setup file. [[Glenn|geychaner@mac.com]]
|
Question: Do ikiwiki.cgi and the RCS post-commit script sanitize the $PATH separately from bin/ikiwiki? If not, then bin/ikiwiki is probably right to sanitize the $PATH; otherwise you've created a security hole with access to the account that ikiwiki is SUID to. It'd be nice if /opt/local/bin were earlier in the $PATH, but that can be changed (as noted) in the setup file. [[Glenn|geychaner@mac.com]] (Also the person who started this by filing an issue with MacPorts; I'm experimenting with ikiwiki for collaborative documentation.)
|
||||||
|
|
Loading…
Reference in New Issue