Re: Transaction names in post Uris webdav
From: Ben Collins-Sussman <sussman_at_red-bean.com>
Date: Thu, 5 Feb 2009 10:03:22 -0600
I don't think there's a realistic attack vector here, for two reasons:
1. Most (sane) apache configurations only allow authenticated commits.
2. mod_dav_svn already prevents 'multi-author' commits. Whenever a
------------------------------------------------------
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.