You are here: Foswiki>Tasks Web>Item14639 (20 Jan 2020, MichaelDaum)Edit Attach

Item14639: Operational topics in Main, Sandbox webs should be protected from editing non-admins.

pencil
Priority: Security
Current State: Closed
Released In: 2.1.6
Target Release: patch
Applies To: Engine
Component: SecurityTasks
Branches: Release02x01 master Item14288
Reported By: GeorgeClark
Waiting For:
Last Change By: MichaelDaum
On sites with open registration, newly registered users are free to deface any of these topics. It is probably a reasonable change to add an ACL to all of these topics ALLOWTOPICCHANGE = AdminGroup. We've had a few of these defaced on Foswiki.org at times.

$ grep -L ALLOWTOPICCHANGE *
AdminUserLeftBar.txt
GroupViewTemplate.txt
PatternSkinUserViewTemplate.txt
UserHomepageHeader.txt
UserListByDateJoined.txt
UserListByLocation.txt
UserListHeader.txt
UserList.txt
WebAtom.txt
WebChanges.txt
WebCreateNewTopic.txt
WebHome.txt
WebIndex.txt
WebLeftBarExample.txt
WebRss.txt
WebSearchAdvanced.txt
WebSearch.txt
WebTopicList.txt
WikiGroups.txt

-- GeorgeClark - 26 Feb 2018

Also, in the Sandbox web, these should also be protected from defacement: (Maybe not the Comment* topics.)

CommentPluginExampleComments.txt
CommentPluginExamples.txt
CommentPluginTemplateExample.txt
WebAtom.txt
WebChanges.txt
WebCreateNewTopic.txt
WebIndex.txt
WebLeftBarExample.txt
WebRss.txt
WebSearchAdvanced.txt
WebSearch.txt
WebTopicList.txt

-- GeorgeClark - 26 Feb 2018

Web* topics in Main, Sandbox and System should all be write protected. Those User* topics in Main should probably be deleted as they are of questionable value. Any *LeftBar should be write protected, only editable by the person it is used by. PatternSkinUserViewTemplate should be relocated to System. WikiGroups obviously needs to be write protected only editable by AdminGroup and RegistrationAgent.

-- MichaelDaum - 01 Mar 2018
 

ItemTemplate edit

Summary Operational topics in Main, Sandbox webs should be protected from editing non-admins.
ReportedBy GeorgeClark
Codebase 2.1.5, trunk
SVN Range
AppliesTo Engine
Component SecurityTasks
Priority Security
CurrentState Closed
WaitingFor
Checkins distro:69289169b9ee distro:83c28bd8cf10
TargetRelease patch
ReleasedIn 2.1.6
CheckinsOnBranches Release02x01 master Item14288
trunkCheckins
masterCheckins distro:69289169b9ee distro:83c28bd8cf10
ItemBranchCheckins distro:69289169b9ee
Release02x01Checkins distro:69289169b9ee
Release02x00Checkins
Release01x01Checkins
Topic revision: r6 - 20 Jan 2020, MichaelDaum
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License    Legal Imprint    Privacy Policy