[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Web Interfaces (was Re: Newbie Questions)

From: Ximon Eighteen <ximon.eighteen_at_int.greenpeace.org>
Date: 2006-01-10 09:36:34 CET

Holger Stratmann wrote:
> Ximon Eighteen wrote:
>
>>> access permissions in ViewVC?
>>
>>
>> It doesn't.
>
>
> Ah. Good to know :-(
>
>> I hacked my ViewCVS ...... using Apache to enforce access controls by
>> URL and using Python code
>
>
> Hmm - are you sure there's no way to "circumvent" path based access? I
> had this problem with WebSVN 1.x before it supported path based access:
> You could still access files if you just passed the correct parameters!

Possibly, but I modified ViewCVS to not serve content, history or file
properties or anything without a permissions check first so I doubt it
could be done through a ViewCVS URL - but like I say below I'm not
saying it was production quality.

> is exactly the reason I don't want to "hack" stuff like that myself.
> Producing "production quality" code that can be committed involves a
> rather large overhead ("do I REALLY know what I'm doing?"), doing it
> just for yourself causes lots of headaches in the long run...

Completely agreed. In our case the 'hack' was acceptable, but it was not
fully tested and probably not secure - but the people we were aiming the
controls at would not have breached it.

X

-- 
----------------------------------------------------------
GPI ICT Application Development Team Leader
MSN   : ximon_eighteen@hotmail.com  Yahoo!: ximon18
ICQ   : 315597094                   Desk  : +31 20 7182134
GMail : ximon.eighteen@gmail.com    Mobile: +31 6 42594359
----------------------------------------------------------
---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@subversion.tigris.org
For additional commands, e-mail: users-help@subversion.tigris.org
Received on Tue Jan 10 09:41:00 2006

This is an archived mail posted to the Subversion Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.