[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: SVN Security

From: Stephen Davis <subversion_at_soundgeek.org>
Date: 2006-04-13 19:32:10 CEST

On Apr 13, 2006, at 8:49 AM, David Anderson wrote:

> * Timo Wendt <twendt@online.de> [2006-04-13 17:10:35]:
>
>> Another thing that bothers me is the auth cache and it even on per
>> default. Saving clear text passwords on disk is bad. In my case the
>> file was even world readable even thogh the book states it is only
>> readable by the owner. I understand that this feature is nice for
>> usage, but is there no way of shutting it off completely apart from
>> changing the source code, which I did? As long as this feature is
>> available, users will use it. Users always find nice ways to make
>> their work easiest.
>
> This is directly addressed in the FAQ on the website:
>
> http://subversion.tigris.org/faq.html#plaintext-passwords
>
> Also, something which the reply does not point out is that we are
> progressively offering integration with desktop keyring services. I
> know that we have this on OS X, and it should be possible to
> contribute patches for other desktops which provide this service, such
> as Gnome or KDE.

I know 1.2 added "keychain" support on Windows but is this really
also true on OS X? When did that support get added? I don't see any
subversion-esque entries in my keychain...

If somebody would like to point me at the right chunk of svn code
where this would go, I'd be happy to take a stab at it.

stephen

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@subversion.tigris.org
For additional commands, e-mail: users-help@subversion.tigris.org
Received on Thu Apr 13 19:41:58 2006

This is an archived mail posted to the Subversion Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.