• Do not register here on develop.twiki.org, login with your twiki.org account.
• Use View topic Item7848 for generic doc work for TWiki-6.1.1. Use View topic Item7851 for doc work on extensions that are not part of a release. More... Close
• Anything you create or change in standard webs (Main, TWiki, Sandbox etc) will be automatically reverted on every SVN update.
Does this site look broken?. Use the LitterTray web for test cases.

The testcase is simple.

Delete the lib/LocalSite.cfg so it is like starting on a fresh install.

Run configure. Save a password.

Go back and finish the configure.

When you hit the final next, configure is supposed to ask for the password you set earlier. But instead it gives this error and asks for an initial password to be set.

You have not defined a password. You can set one below

You can repeat this as often as you like. Each time you save in configure it asks for a new password and never writes the password in LocalSite.cfg

It does however create the LocalLib.cfg and saves all the other configurations!

This is a security bug = requirement.

-- KJL

Note. I found this when I tested a release that was supposed to be the first beta. But there is no way I will release a beta with this security bug open.

-- KJL

Fixed. Closed, because code has not been released yet.

CC

If you encountered the problem of the password not being saved:
You will need to delete the line $TWiki::cfg{Password} = ''; from LocalSite or the new password will still not be written.

AC

ItemTemplate
Summary configure does not save password (security issue)
ReportedBy TWiki:Main.KennethLavrsen
Codebase ~twiki4
SVN Range TWiki-4.1, Mon, 30 Oct 2006, build 11853
AppliesTo Engine
Component

Priority Urgent
CurrentState Closed
WaitingFor

Checkins 11902
TargetRelease n/a
Edit | Attach | Watch | Print version | History: r6 < r5 < r4 < r3 < r2 | Backlinks | Raw View |  Raw edit | More topic actions
Topic revision: r6 - 2006-11-06 - ArthurClemens
 
This site is powered by the TWiki collaboration platform Powered by PerlCopyright © 2008-2024 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback