[4suite-dev] URIs in the repo, revisited (addendum)

Uche Ogbuji uche.ogbuji at fourthought.com
Wed Dec 11 20:15:37 MST 2002


On Wed, 2002-12-11 at 20:02, Mike Olson wrote:
> > 
> > Well, of couyrse we'd have to add facility for this.  I didn't say that
> > they could do so with 4Suite as it is.
> > 
> > A "LocalDocumentRoot" option would be one way.  I would not want it to
> > be yes/no, but rather a list of 4ss users who have permission to access
> > local file system.
> 
> I've been thinking about this some more.  I think we should just disable
> file system access (because it is a security hole) and leave it at
> that.  We have no requests from anyone (users or clients) to drive this
> and it looks like we are comming up with yet another very
> flexible/complex (to the point of being unusable) 4Suite feature "just
> because we can".

We have from at least 2 users: Evan Lenz and me.

Speaking for myself, I most definitely want to have access to the local
file system in certain situations.  As an admin, I would expect 4Suite
to give me the ropes and the responsibility, and not stand in my way.

Therefore I vote against disabling file system access across the board.


> -- 
> Uche Ogbuji                                    Fourthought, Inc.
> http://uche.ogbuji.net    http://4Suite.org    http://fourthought.com
> Tour of 4Suite - http://www.xml.com/pub/a/2002/10/16/py-xml.html
> Proper XML Output in Python - http://www.xml.com/pub/a/2002/11/13/py-xml.html
> RSS for Python - http://www-106.ibm.com/developerworks/webservices/library/ws-pyth11.html
> Debug XSLT on the fly - http://www-106.ibm.com/developerworks/xml/library/x-debugxs.html




More information about the 4suite-dev mailing list