monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] Re: db kill_rev_locally


From: Daniel Carrera
Subject: Re: [Monotone-devel] Re: db kill_rev_locally
Date: Sun, 12 Oct 2008 00:38:01 +0200
User-agent: Thunderbird 2.0.0.17 (Macintosh/20080914)

Bruce Stephens wrote:
Daniel Carrera <address@hidden> writes:
So it can only happen if the developer has SSH access. Tell me if I'm
wrong, but if you want developers to tunnel through SSH they can then
execute Monotone commands including "db execute". Right?

Indeed.  So don't do that.  Instead, offer a monotone server that
people can push to.

1) Some times SSH is the only choice.

2) SSH has security features that some projects may find very important. You don't always want people to be able to read the stuff you send to the server.

I offered what I believe to be a simple way to address the security issue without adversely affecting users who want to use these commands.


Daniel.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]