Re: [SVN-DEV] RE: Authorization [2]

From: C. Scott Ananian <cananian_at_lesser-magoo.lcs.mit.edu>
Date: 2001-09-05 16:57:51 CEST

On Wed, 5 Sep 2001, Sander Striker wrote:

> No, that would fail directly in the following situation:
> /foo/bar (this path has a DACL for certain users)
> Now a developer decides to rename or move bar and you get:
> /foo/baz
> This path doesn't have the DACL. So in the new revision the denied
> users can get in. Consider replacing the DACL to affect /foo/baz.

I actually think this is a *feature*. If the user has read permission in
bar but write permission in baz, then they can copy the file to baz in
order to "work on it". If they have write permission in bar, then
*moving* the file from bar to baz is permissible. This helps divide the
tree into security zones. If you don't want the DACL stripped, then you
shouldn't give the user permission to copy/move the file from the
DACL-controlled root. If you want to keep them from moving to /foo/baz,
there should be a DACL on /foo.

