Community
Participate
Working Groups
Using a local orion server 0. In your server config file, ensure that the "orion.file.anonymous.read=true" server option is NOT set. 1. Launch the Orion server. 2. As user A, create a project and put some files in it. Copy its internal project id (for example, 'kS'). 3. As user B, log in and create a new site. 4. Set up the site like this, using the other user's project id from step 2: Path Mounted at: /kS/ / 5. Start the site, and view it in your browser. We expect that, because user B launched the site and does not have the right to access 'kS', there should be an error. However, the site loads and can be used to view the user A's files, this is bad.
http://git.eclipse.org/c/orion/org.eclipse.orion.server.git/commit/?h=checkrights_382760
Let's defer this to 1.0. Because we allow global anonymous read on our hosted servers this isn't a blocking problem for us.
Pushed to master with test: http://git.eclipse.org/c/orion/org.eclipse.orion.server.git/commit/?id=daa3b276ee4104a804442428bd8556b28e91e769