Edgewall Software
Modify

Opened 17 years ago

Closed 17 years ago

#4344 closed defect (invalid)

Trac doesn't care about SVN authz permission

Reported by: ploum@… Owned by: Christian Boos
Priority: normal Milestone:
Component: version control/browser Version: 0.10.2
Severity: normal Keywords:
Cc: Branch:
Release Notes:
API Changes:
Internal Changes:

Description

You can set a subversion repository so that some users have no read-access in some subfolders.

This can be useful if, for example, you want to work secretely on some part of the project or if you have to store password and things like that or simply that some part of the project are just too personnal.

But Trac does not care about that svn.authz file and every trac user that has browse_source right can see the whole svn repository.

This is, IMHO, a bug and it could be very annoying if the user is not aware of this bug and doesn't test his trac installation.

Attachments (0)

Change History (3)

comment:1 by Noah Kantrowitz <coderanger@…>, 17 years ago

Just use the authz_file option in trac.ini.

comment:2 by anonymous, 17 years ago

And is documented in FineGrainedPermissions. That page probably needs to be made easier to find in the documation. Possibly using a small section in TracPermissions instead of a see also note at the bottom? Or maybe an entry on the main index?

comment:3 by ploum@…, 17 years ago

Resolution: invalid
Status: newclosed

indeed, I was not aware about this option. It works very well, thanks :-)

Modify Ticket

Change Properties
Set your email in Preferences
Action
as closed The owner will remain Christian Boos.
The resolution will be deleted. Next status will be 'reopened'.
to The owner will be changed from Christian Boos to the specified user.

Add Comment


E-mail address and name can be saved in the Preferences .
 
Note: See TracTickets for help on using tickets.