Tags:
create new tag
view all tags

Question

My question is general. By definition and with intent, Twiki is clearly very open. What security is in place or optional? Can it be configured to prevent users from calling externally hosted scripts (e.g. javascript) that could potentially be malicious? What options are there to enable open collaboration while protecting the OS and connected infrastructure from malicious intent?

Environment

TWiki version: TWikiRelease01Feb2003
TWiki plugins: DefaultPlugin, EmptyPlugin, InterwikiPlugin
Server OS:  
Web server:  
Perl version:  
Client OS:  
Web Browser:  

-- TWikiGuest - 02 Jul 2004

Answer

Q
What security is in place or optional?
A
Lots. RTFM.

Q
Can it be configured to prevent users from calling externally hosted scripts (e.g. javascript) that could potentially be malicious?
A
Not clear what you mean. If you mean "can I filter URLs", the answer is you would have to write code. If that isn't the question, what is?

Q
What options are there to enable open collaboration while protecting the OS and connected infrastructure from malicious intent?
A
RTFM, and the Apache/other webserver manuals.

-- CrawfordCurrie - 03 Jul 2004

TWiki has many security options needed in a corporate environment. It is unlikely that the underlying file system can get compromized.

You can create groups and lock down individual pages are whole webs. Collaboration works best without too many restrictions; there is however a psychological barrier to open up content. See TWikiAccessControl

-- PeterThoeny - 03 Jul 2004

Edit | Attach | Watch | Print version | History: r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions
Topic revision: r3 - 2004-07-03 - PeterThoeny
 
  • Learn about TWiki  
  • Download TWiki
This site is powered by the TWiki collaboration platform Powered by Perl Hosted by OICcam.com Ideas, requests, problems regarding TWiki? Send feedback. Ask community in the support forum.
Copyright © 1999-2026 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.