[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Working copy path for hooks

From: Stefan Küng <tortoisesvn_at_gmail.com>
Date: 2007-11-14 19:04:43 CET

braulio.horta@embraer.com.br wrote:
> I see it is necessary to set the working copy path for client-side
> scripts (in nightly build versions).
> But i think that it would be nice to run a script independently from
> working copy path, maybe using *(star) for working copy path.
> So you use can determine the working copy path(target) using %path% or
> %paths% variable inside the script.
> This way, it would be possible to set a script for all working copies.

Sorry, but I won't do that:
if we would allow something like this, someone could hack your
repository, place some bad exe in there and set up the hook. And then
*all* your devs would have that bad exe executed with local user rights
and not even knowing it.

By forcing users to set up those hook scripts manually we can make sure
that something like this can't happen. Yes, it's more work, but much
more secure.

Stefan

-- 
        ___
   oo  // \\      "De Chelonian Mobile"
  (_,\/ \_/ \     TortoiseSVN
    \ \_/_\_/>    The coolest Interface to (Sub)Version Control
    /_/   \_\     http://tortoisesvn.net
---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@tortoisesvn.tigris.org
For additional commands, e-mail: users-help@tortoisesvn.tigris.org
Received on Wed Nov 14 19:05:22 2007

This is an archived mail posted to the TortoiseSVN Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.