Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Script allows read-only users to read credentials of other users #12

Closed
C-Duv opened this issue Jun 15, 2017 · 2 comments
Closed

Script allows read-only users to read credentials of other users #12

C-Duv opened this issue Jun 15, 2017 · 2 comments

Comments

@C-Duv
Copy link

C-Duv commented Jun 15, 2017

Because the script allow opening/viewing itself, if the script is located in $root_path a read only user can read credentials of others users (in $auth_users configuration variable) and then gain write access.

Proposition: add an option to disallow the script to view itself.

@C-Duv C-Duv changed the title Script allow readonly users to read credentials of other users Script allows read-only users to read credentials of other users Jun 15, 2017
@alexantr
Copy link
Owner

This filemanager was created as developer tool. And I'm planning to remove some features which not usable for me as developer: hiding hidden files, readonly users etc.
Please use elFinder if you want to give access to unreliable users. Or fork this repo and create new features.

@alexantr
Copy link
Owner

Sorry, but I removed supporting read-only users and hidding hidden files.

Please try tinyfilemanager

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants