• Do not register here on develop.twiki.org, login with your twiki.org account.
• Use View topic Item7848 for generic doc work for TWiki-6.1.1. Use View topic Item7851 for doc work on extensions that are not part of a release. More... Close
• Anything you create or change in standard webs (Main, TWiki, Sandbox etc) will be automatically reverted on every SVN update.
Does this site look broken?. Use the LitterTray web for test cases.

I can see that the Auto-Attach Files feature can be a handy tool for hackers, but it does not fit into the corporate space of TWiki. Problems:

  • It defeats the complete audit trail TWiki gives (there are UnknownUsers doing suff)
  • It is seen as a security issue if an UnknownUser can change content (see below e-mail)

Therefore we should turn this feature off by default.

E-mail received:

> I prefere to email you than ask the support web as this is a little
> delicate.
> On our Main/WebHome page someone has attached 131 png files. I saw these
> last week and removed them but they have now been re-attached by
> UnknownUser. They look like this
> 4c7bcbae97ad322481c5cf3d35d7ac9b.png manage 0.2 K 05 Nov 2006 - 03:06
> UnknownUser
> They seem harmless enough but my problem is that I can not find how they
> were attached. There is nothing obvious from the web logs or the Twiki
> logs. I did remove them by hand on the unix shell however. Either Twiki
> has someone re-attached them or someone is playing around. We have
> kerberos authentication here and one has to be registered and
> authenticated to edit or attach.
> Can you spread some light on this please.

-- PTh

Done, 12000. (nice round number)

-- PTh

4.1.0 released


Summary Turn off {AutoAttachPubFiles} in default distribution
ReportedBy TWiki:Main.PeterThoeny
Codebase ~twiki4
SVN Range TWiki-4.1, Thu, 09 Nov 2006, build 11947
AppliesTo Engine

Priority Urgent
CurrentState Closed

Checkins 12000
TargetRelease minor
Edit | Attach | Watch | Print version | History: r5 < r4 < r3 < r2 < r1 | Backlinks | Raw View |  Raw edit | More topic actions
Topic revision: r5 - 2007-01-16 - KennethLavrsen
This site is powered by the TWiki collaboration platform Powered by PerlCopyright © 2008-2024 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback