Tags:
create new tag
view all tags

SID-02374: How to deny TWikiGuest access to /bin/statistics

Status: Answered Answered TWiki version: 6.0.2 Perl version: 5.10.1
Category: CategoryAccessControl Server OS: CentOS 6.10 kernel 2.6.32-754.2.1.el6.x86_64 Last update: 7 years ago

The local security mavens have decided (after a year) that there's a problem with /bin/statistics in that anyone can type in the full url and it will run as TWikiGuest for some reason. I thought I had done the right stuff with twiki.conf and TWikiGuest can't do anything bad that I know of but this is cited as a cross-site scripting problem. So 1) Can I totally disable TWikiGuest, or does that have consequences? 2) Can I specifically deny access to /bin/statistics by TWikiGuest? 3) Am I doing something wrong, ie should outside users always get n when trying to access anything in the TWiki directory structure?

-- John Huber - 2018-10-09

Discussion and Answer

If you use the default template login you can simply add statistics to the {AuthScripts} configure setting.

-- Peter Thoeny - 2018-10-10

      Change status to:
ALERT! If you answer a question - or someone answered one of your questions - please remember to edit the page and set the status to answered. The status selector is below the edit box.
SupportForm
Status Answered
Title How to deny TWikiGuest access to /bin/statistics
SupportCategory CategoryAccessControl
TWiki version 6.0.2
Server OS CentOS 6.10 kernel 2.6.32-754.2.1.el6.x86_64
Web server apache: httpd-2.2.15-69.sl6.x86_64
Perl version 5.10.1
Browser & version any
Edit | Attach | Watch | Print version | History: r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions
Topic revision: r2 - 2018-10-10 - PeterThoeny
 
  • Learn about TWiki  
  • Download TWiki
This site is powered by the TWiki collaboration platform Powered by Perl Hosted by OICcam.com Ideas, requests, problems regarding TWiki? Send feedback. Ask community in the support forum.
Copyright © 1999-2026 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.