From 706bf876eab25158d34558fc2b0b0979a3dedcbf Mon Sep 17 00:00:00 2001 From: intrigeri Date: Sat, 17 Dec 2016 11:11:44 +0000 Subject: [PATCH] Report authorization bypass via RCS revert. --- ...thorization_if_affected_files_were_renamed.mdwn | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 doc/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed.mdwn diff --git a/doc/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed.mdwn b/doc/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed.mdwn new file mode 100644 index 000000000..8ac62e554 --- /dev/null +++ b/doc/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed.mdwn @@ -0,0 +1,14 @@ +1. We have a `$srcdir/writable/page.mdwn` source file in Git. +2. ikiwiki is configured to allow edits via the CGI in `writable/*`, + but nowhere else. +2. Modify `$srcdir/writable/page.mdwn`, commit ⇒ commit `$id`. +3. `git mv $srcdir/writable/page.mdwn $srcdir/read-only/page.mdwn` + +⇒ The web interface allows reverting commit `$id` (presumably because +it changes files only in `$srcdir/writable`). This operation +effectively modifies `$srcdir/read-only/page.mdwn`, which feels wrong. +My guess is that `check_canchange` does not take into account that Git +will automatically detect that the file affected by the to-be-reverted +commit has moved, and modify the file in its new location +when reverting. + -- 2.39.2