Export to GitHub

fredistrano - issue #42

Security Issues?


Posted on Aug 15, 2008 by Massive Giraffe

What version of the product are you using? On what operating system? .3.2 on Ubuntu Server.

Please provide any additional information below.

My web server normally creates new site accounts in home, owned by the user of the home account (say, "clientname"). Up until this point, I have let it be that way. However when I was first starting to work with Fredistrano, I discovered that this wouldn't work. I needed to change the user permissions to www-data (apache user in Ubuntu) and then rsync would actually deliver the files to the public_html directory.

Now that I have deployed the first test installation on my CMS, I realize that the files are actually deployed as writable by the server, which isn't good. My config file is 644.

Anything I'm doing wrong?

Comment #1

Posted on Aug 15, 2008 by Massive Cat

hi rbra... could you contact me by this form => http://fbollon.net/contact so that we can investigate together on this issue.

Comment #2

Posted on Aug 16, 2008 by Quick Rabbit

There might be an issue with our usage of the recursive chmod command. It should be fixed in our next beta release (0.4). At least it works on my laptop ;)

Comment #3

Posted on Sep 24, 2008 by Massive Cat

(No comment was entered for this change.)

Comment #4

Posted on Sep 25, 2008 by Quick Rabbit

(No comment was entered for this change.)

Status: Fixed

Labels:
Type-Defect Priority-High OpSys-All Security Component-Logic Milestone-Release1.0