User that WebCatalog/Unix runs as

This WebDNA talk-list message is from

2000


It keeps the original formatting.
numero = 32384
interpreted = N
texte = Something for unix testers to try out: in order to deal with security issues that customers run into with 3.0.8 (the fact that WebCatalog runs as user nobody, and newly-uploaded files are not owned by user nobody), we have expanded the preferences a bit to provide a configurable username.If you modify the WebCatalog Prefs file's UnixUser preference line and restart WebCatalog, then WebCatalog will run as that user.So if you have a user fred who belongs to group webcatalog, then you can set the UnixUser preference to fred, and WebCatalog will run as that user. Additionally, you can change the ownership of all the files+directories that WebCatalog controls (http/html/WebCatalog/ for instance) to be owned by group webcatalog.Now user fred or any other user who belongs to group webcatalog can upload files via ftp and WebCatalog will be able to read/write to them.Yes, we understand that all the users have to belong to the same group, and that they could potentially write destructive WebDNA that interferes with other members of that group. But this is an intermediate step towards the ultimate security model, and it's better than 3.0 is now.Grant Hulbert, Director of Engineering ********************************** Smith Micro, Internet Solutions Div | eCommerce (WebCatalog) 16855 West Bernardo Drive, #380 | ------------------------- San Diego, CA 92127 | Software & Site Development Main Line: (858) 675-1106 | http://www.smithmicro.com Fax: (858) 675-0372 **********************************############################################################# This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to To switch to the INDEX mode, E-mail to Send administrative queries to Associated Messages, from the most recent to the oldest:

    
  1. Re: User that WebCatalog/Unix runs as (GHulbert@smithmicro.com 2000)
  2. Re: User that WebCatalog/Unix runs as (John Butler 2000)
  3. User that WebCatalog/Unix runs as (GHulbert@smithmicro.com 2000)
Something for unix testers to try out: in order to deal with security issues that customers run into with 3.0.8 (the fact that WebCatalog runs as user nobody, and newly-uploaded files are not owned by user nobody), we have expanded the preferences a bit to provide a configurable username.If you modify the WebCatalog Prefs file's UnixUser preference line and restart WebCatalog, then WebCatalog will run as that user.So if you have a user fred who belongs to group webcatalog, then you can set the UnixUser preference to fred, and WebCatalog will run as that user. Additionally, you can change the ownership of all the files+directories that WebCatalog controls (http/html/WebCatalog/ for instance) to be owned by group webcatalog.Now user fred or any other user who belongs to group webcatalog can upload files via ftp and WebCatalog will be able to read/write to them.Yes, we understand that all the users have to belong to the same group, and that they could potentially write destructive WebDNA that interferes with other members of that group. But this is an intermediate step towards the ultimate security model, and it's better than 3.0 is now.Grant Hulbert, Director of Engineering ********************************** Smith Micro, Internet Solutions Div | eCommerce (WebCatalog) 16855 West Bernardo Drive, #380 | ------------------------- San Diego, CA 92127 | Software & Site Development Main Line: (858) 675-1106 | http://www.smithmicro.com Fax: (858) 675-0372 **********************************############################################################# This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to To switch to the INDEX mode, E-mail to Send administrative queries to GHulbert@smithmicro.com

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

WebCat Linux: Could not create pipeKey segment (2000) [WebDNA] Error 500 with SUMM=T (2017) Exclamation point (1997) WebCatalog f2 Installation (1997) problems with 2 tags (1997) [price] maddness (2002) WebDNA update from Smith Micro (2002) THANKS (1997) Payments -> Bank Accounts (2005) WebCat2b12 CGI Mac -- Problems propagating the cart through frames...still (1997) Is this possible, WebCat2.0 and checkboxes (1997) Setting a range in a search (1998) WebCatalog [FoundItems] Problem - AGAIN - (1997) WebCat2b14MacPlugIn - [include] doesn't hide the search string (1997) Search crashing server (1998) shipcost (1997) I got caught! (2003) Default admin bug and how tech support reacted to it. (2000) RE: Automatic Forwarding using WebCat (1997) old mail...problem with listserv? (1998)