X-Git-Url: http://git.vanrenterghem.biz/git.ikiwiki.info.git/blobdiff_plain/2c64a9f6f1fc2996d61a055339e6afd7d470495a..99292550fdf3c5bf9feb4a665e2de99f5cfc0d35:/doc/security.mdwn diff --git a/doc/security.mdwn b/doc/security.mdwn index 956351d70..77552b1b2 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -10,6 +10,8 @@ to be kept in mind. # Probable holes +_(The list of things to fix.)_ + ## svn commit logs Anyone with svn commit access can forge "web commit from foo" and make it @@ -60,7 +62,7 @@ this wiki, BTW. ## page locking can be bypassed via direct svn commits -A [[lock]]ed page can only be edited on the web by an admin, but +A locked page can only be edited on the web by an admin, but anyone who is allowed to commit direct to svn can bypass this. This is by design, although a subversion pre-commit hook could be used to prevent editing of locked pages when using subversion, if you really need to.