Re: [PATCH] Introduce AuthzSVNGroupsFile configuration option for mod_authz_svn
From: Philip Martin <philip.martin_at_wandisco.com>
Date: Mon, 28 Jan 2013 11:10:12 +0000
Evgeny Kotkov <evgeny.kotkov_at_visualsvn.com> writes:
> * With includes in the configuration files an evil-doer could perform
Are you claiming the evil-doer could access the included files but not
> * As far as I understand, including huge arbitrary files for a single
How does breaking an single authz file into multiple files makes this
> * Includes add dynamic behavior in the authz scheme. Without them, the
I don't see what is "dynamic" about the include proposal. It's just
> - Includes might require merging of access rules and configuration chunks from
It's simple text concatenation. We have an authz validation utility
> - Finally, the solution with a new directive follows the pattern
So we now have 3 directives, do we need another directive for
Also your directive needs a separate implementation in mod_authz_svn,
-- Certified & Supported Apache Subversion Downloads: http://www.wandisco.com/subversion/downloadReceived on 2013-01-28 12:11:01 CET |
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.