[dokuwiki] Re: securing images in namespaces

I uploaded the file (.pdf) into the namespace esp.  when I click on upload 
file and select the name space the file is in the list of files.

from a different namespace I have a page with a link to the image using 
the {{}} syntax. 
a user that have none access to the esp namespace can click on the link in 
the different namespace and is able to open the image. 
he can not open any page in the second namespace.

I had hoped that security would limit this access.

-------------------------------------------------
Larry Simonsen
System Analyst
Flowserve Corporation   1350 North Mountain Springs Parkway Springville, 
UT 84883   Phone: 801-489-2450   Fax: 801-491-1750
-------------------------------------------------
All opinions expressed herein are my own and reflect, in no way, those of 
my employer.
-------------------------------
NOTICE:  The information contained in this e-mail and any attachment(s) 
thereto is confidential and may contain attorney-client privileged 
communications or proprietary information. If you are not the intended 
recipient, you are hereby notified that any dissemination, distribution, 
or copying of this communication is strictly prohibited. If you have 
received this communication in error, please notify the sender immediately 
and delete the e-mail from your computer system without retaining any 
copies. Thank you.




From:   Michael Hamann <michael@xxxxxxxxxxxxxxxx>
To:     <dokuwiki@xxxxxxxxxxxxx>
Date:   12/16/2011 04:13 PM
Subject:        [dokuwiki] Re: securing images in namespaces
Sent by:        <dokuwiki-bounce@xxxxxxxxxxxxx>



Hi,

On Sat, Dec 17, 2011 at 12:07 AM,  <LSimonsen@xxxxxxxxxxxxx> wrote:
> I have uploaded an pdf file as an image and can link to it in a name 
space.
>  a page in another namespace that links to this image can open it even
> though the user does not have access to the namespace.  is there a 
control I
> have not checked.  the ACL is setup and works for pages in the 
namespace.

Are you sure you have uploaded the image in the namespace that is
protected? Media files are organized in namespaces similar to pages,
only namespace ACLs are applied to media files. Media files are not
attached to pages, so it doesn't matter in which page the media files
was originally used.

Michael
-- 
DokuWiki mailing list - more info at
http://www.dokuwiki.org/mailinglist


Other related posts: