User that WebCatalog/Unix runs as

This WebDNA talk-list message is from

2000


It keeps the original formatting.
numero = 32384
interpreted = N
texte = Something for unix testers to try out: in order to deal with security issues that customers run into with 3.0.8 (the fact that WebCatalog runs as user nobody, and newly-uploaded files are not owned by user nobody), we have expanded the preferences a bit to provide a configurable username.If you modify the WebCatalog Prefs file's UnixUser preference line and restart WebCatalog, then WebCatalog will run as that user.So if you have a user fred who belongs to group webcatalog, then you can set the UnixUser preference to fred, and WebCatalog will run as that user. Additionally, you can change the ownership of all the files+directories that WebCatalog controls (http/html/WebCatalog/ for instance) to be owned by group webcatalog.Now user fred or any other user who belongs to group webcatalog can upload files via ftp and WebCatalog will be able to read/write to them.Yes, we understand that all the users have to belong to the same group, and that they could potentially write destructive WebDNA that interferes with other members of that group. But this is an intermediate step towards the ultimate security model, and it's better than 3.0 is now.Grant Hulbert, Director of Engineering ********************************** Smith Micro, Internet Solutions Div | eCommerce (WebCatalog) 16855 West Bernardo Drive, #380 | ------------------------- San Diego, CA 92127 | Software & Site Development Main Line: (858) 675-1106 | http://www.smithmicro.com Fax: (858) 675-0372 **********************************############################################################# This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to To switch to the INDEX mode, E-mail to Send administrative queries to Associated Messages, from the most recent to the oldest:

    
  1. Re: User that WebCatalog/Unix runs as (GHulbert@smithmicro.com 2000)
  2. Re: User that WebCatalog/Unix runs as (John Butler 2000)
  3. User that WebCatalog/Unix runs as (GHulbert@smithmicro.com 2000)
Something for unix testers to try out: in order to deal with security issues that customers run into with 3.0.8 (the fact that WebCatalog runs as user nobody, and newly-uploaded files are not owned by user nobody), we have expanded the preferences a bit to provide a configurable username.If you modify the WebCatalog Prefs file's UnixUser preference line and restart WebCatalog, then WebCatalog will run as that user.So if you have a user fred who belongs to group webcatalog, then you can set the UnixUser preference to fred, and WebCatalog will run as that user. Additionally, you can change the ownership of all the files+directories that WebCatalog controls (http/html/WebCatalog/ for instance) to be owned by group webcatalog.Now user fred or any other user who belongs to group webcatalog can upload files via ftp and WebCatalog will be able to read/write to them.Yes, we understand that all the users have to belong to the same group, and that they could potentially write destructive WebDNA that interferes with other members of that group. But this is an intermediate step towards the ultimate security model, and it's better than 3.0 is now.Grant Hulbert, Director of Engineering ********************************** Smith Micro, Internet Solutions Div | eCommerce (WebCatalog) 16855 West Bernardo Drive, #380 | ------------------------- San Diego, CA 92127 | Software & Site Development Main Line: (858) 675-1106 | http://www.smithmicro.com Fax: (858) 675-0372 **********************************############################################################# This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to To switch to the INDEX mode, E-mail to Send administrative queries to GHulbert@smithmicro.com

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

writing db to disk (1997) Looking up two prices in database? (1997) New servers and new inline cache (1997) shipcost (1997) Shownext! (1998) Credit card processing options. . . (1997) [SEARCH] Context for SKU prices not working... (1998) [WebDNA] Grep (2009) replace using &append=T (2007) Mac Programs (1998) Add more fields to an existent data base (1997) Here's how to kill a Butler Database. (1997) [WebDNA] Nested Search (2008) WebCat2b15MacPlugIn - [authenticate] not [protect] (1997) All choices on IE different than Netscape (1997) WebCat2b12 - nesting [tags] (1997) Summing fields (1997) Playin Tricks (2006) no global [username] or [password] displayed ... (1997) 2.0 Info (1997)