Modify ↓
Opened 15 years ago
Closed 15 years ago
#6250 closed enhancement (fixed)
Improve security
Reported by: | Álvaro Iradier | Owned by: | Álvaro Iradier |
---|---|---|---|
Priority: | high | Component: | TracWikiPrintPlugin |
Severity: | normal | Keywords: | |
Cc: | Trac Release: | 0.11 |
Description
Now, users with TRAC_ADMIN permission can select any file from the system as css, header, or footer, and preview it.
Two fixes should be made:
- TracWikiPrintPlugin should not require TRAC_ADMIN permissions for basic configuration. Create a new permission, like WIKIPRINT_ADMIN, to allow non-admin user users to configure Wiki Print.
- Allow the TRAC_ADMIN user to disable using files from filesystem in Wiki Print. If the option is disabled, only URLs will be allowed to select css, header or footer.
Attachments (0)
Change History (2)
comment:1 Changed 15 years ago by
Status: | new → assigned |
---|
comment:2 Changed 15 years ago by
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Note: See
TracTickets for help on using
tickets.
(In [7699]) New version 1.7