Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-9332

Improve security by only giving programming rights to scripts signed by a privileged user

    Details

    • Type: New Feature
    • Status: In Progress
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 5.1
    • Fix Version/s: None
    • Component/s: Security
    • Labels:
      None
    • Difficulty:
      Unknown
    • Similar issues:

      Description

      The actual PR system has many flaws, most of them being due to the fact that PR are given to documents and not to scripts. To fix these issues, we should introduce the concept of "signed" scripts : when a privileged user wants to give PR to a script, he would sign it. Then a script would be granted PR if and only if we can find a valid signature for it.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                softec Denis Gervalle
                Reporter:
                thomas_delafosse Thomas Delafosse
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated: