[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Monotone-devel] Re: How secure are group names?
From: |
Peter Simons |
Subject: |
[Monotone-devel] Re: How secure are group names? |
Date: |
02 Dec 2003 16:20:09 +0100 |
graydon hoare writes:
> they can get it just by requesting the .db file in a GET.
Well, that shouldn't be an issue. My system does not allow
this, and I think it would be tough to configure it so it
did. :-)
> if not, well, there is no security on reading groups
> anyways; all groups are readable if you ask for the right
> name.
And if you don't know the name? Could you find out, which
groups exist?
> I had thought you'd just keep such a server private.
Yes, now that I have finally got the mailto posts working,
I like an e-mail based solution much better anyway, so this
is not a serious issue.
> I think "list unknown" should do that.
| peti:~/monoprojects/public/homepage$ monotone status
| Old manifest: 31629d04e573e01a111eaf6f5f9a09cbbbb90950
| New manifest: 31629d04e573e01a111eaf6f5f9a09cbbbb90950
| Summary of changes:
| no changes
| peti:~/monoprojects/public/homepage$ touch new-file
| peti:~/monoprojects/public/homepage$ monotone ls unknown
| peti:~/monoprojects/public/homepage$ monotone ls unknown --verbose
| monotone: opening rcfile '/home/simons/.monotonerc' ... monotone: ok
| monotone: executing ls command
| monotone: executing list command
| monotone: manifest path is MT/manifest
| monotone: loading manifest file MT/manifest
| monotone: read 88 manifest entries
| monotone: work path is MT/work
| monotone: no un-committed work file MT/work
| peti:~/monoprojects/public/homepage$ monotone ls ignored --verbose
| monotone: opening rcfile '/home/simons/.monotonerc' ... monotone: ok
| monotone: executing ls command
| monotone: executing list command
Nothing happens.
Peter