Tags:
create new tag
view all tags

Question

I have a Twiki installation where most webs are set so that editing requires username/password authentication but viewing is open.

I have a requirement to lock down one particular web only e.g. by using ALLOWWEBVIEW. I am slightly alarmed that the docs say that this is not very secure.

Is there more information on the nature of this insecurity and is there any way to achieve high security on this one web without having to lock down the whole Twiki?

I have already got Apache to force SSL on that particular web using a redirect, in case that was the problem.

Environment

TWiki version: TWikiRelease01Feb2003
TWiki plugins: DefaultPlugin, EmptyPlugin, InterwikiPlugin
Server OS: Redhat ES 3.0
Web server: Apache
Perl version: 5.8.0
Client OS: Windows
Web Browser: Firefox or IE

-- SimonBlandford - 22 Apr 2004

Answer

With the TWikiRelease01Feb2003 you could include a protected topic into an unprotected topic without authentication (assuming you know the name of the topic to include). This has been fixed. You can upgrade to a recent TWikiBetaRelease, they are usually stable and can be used in a production environment.

-- PeterThoeny - 24 Apr 2004

Edit | Attach | Watch | Print version | History: r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions
Topic revision: r3 - 2004-07-03 - PeterThoeny
 
  • Learn about TWiki  
  • Download TWiki
This site is powered by the TWiki collaboration platform Powered by Perl Hosted by OICcam.com Ideas, requests, problems regarding TWiki? Send feedback. Ask community in the support forum.
Copyright © 1999-2026 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.