Browse files

Deny prune command in operator profile

Using the prune command and setting the rentenion to 0 has the same
effect as the purge command. To prevent harm, a normal operator should
not be able to execute this command.
1 parent a20903b commit 538c4e5a84e103aa6688125d16a5541d40918efc @joergsteffens joergsteffens committed Dec 2, 2016
Showing with 1 addition and 1 deletion.
  1. +1 −1 src/defaultconfigs/bareos-dir.d/profile/operator.conf
@@ -3,7 +3,7 @@ Profile {
Description = "Profile allowing normal Bareos operations."
Command ACL = !.bvfs_clear_cache, !.exit, !.sql
- Command ACL = !configure, !create, !delete, !purge, !sqlquery, !umount, !unmount
+ Command ACL = !configure, !create, !delete, !purge, !prune, !sqlquery, !umount, !unmount
Command ACL = *all*
Catalog ACL = *all*

0 comments on commit 538c4e5

Please sign in to comment.