Skip to content

Make the config directory only accessible to the owning user#170

Merged
tminusplus merged 1 commit intomainfrom
tszucs/config-perms
Apr 17, 2023
Merged

Make the config directory only accessible to the owning user#170
tminusplus merged 1 commit intomainfrom
tszucs/config-perms

Conversation

@tminusplus
Copy link
Copy Markdown
Contributor

@tminusplus tminusplus commented Apr 17, 2023

What was changed

This makes our config directory only accessible to the owning user.

Why?

Ensure a user is unable to read or modify another user's config directory.

Checklist

  • Tested a tcld command with oauth and a pre-created config directory from an older version.
  • Tested a tcld command with oauth and no pre-created config directory.

@tminusplus tminusplus requested a review from mastermanu April 17, 2023 17:01
@tminusplus tminusplus changed the title Make the config directory only accessible to the current user Make the config directory only accessible to the owning user Apr 17, 2023
@tminusplus tminusplus merged commit 6deca65 into main Apr 17, 2023
@tminusplus tminusplus deleted the tszucs/config-perms branch April 17, 2023 18:53
@tminusplus tminusplus restored the tszucs/config-perms branch April 17, 2023 20:23
@tminusplus tminusplus deleted the tszucs/config-perms branch April 17, 2023 20:24
tminusplus added a commit that referenced this pull request Apr 17, 2023
* remove config on logout (#149)

* add create namespace command (#151)

* add namespace delete command (#158)

* bump version in tcld to v0.5.0 (#163)

* Tighten permissions on config files (#170)

---------

Co-authored-by: mattkim <matt@temporal.io>
tminusplus added a commit that referenced this pull request Apr 25, 2023
* remove config on logout (#149)

* add create namespace command (#151)

* add namespace delete command (#158)

* bump version in tcld to v0.5.0 (#163)

* Tighten permissions on config files (#170)

---------

Co-authored-by: mattkim <matt@temporal.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants