[dokuwiki] Patch Attached: Optionally prevent unknown internet users to browse the full media file tree with mediamanager

  • From: Helmut Tischer <htischer@xxxxxxxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Sun, 08 Feb 2009 22:53:19 +0100

mediamanager_no_unknown_users

If a unknown internet user knows the URL of the mediamanager in a DokuWiki,
the person can browse and examine the full media file tree,
even if this is a closed wiki.
Configurable with Admin plugin or $conf['openmediamanager'] this
can be prevented now by simulating a non existing page.
Test:
open the media manager http://example.com/lib/exe/mediamanager.php
while not logged in.
This no longer works with the patch and $conf['openmediamanager']=0;

Helmut

Other related posts:

  • » [dokuwiki] Patch Attached: Optionally prevent unknown internet users to browse the full media file tree with mediamanager - Helmut Tischer