Bug#565738: drupal: shouldn't enable on all sites by default

2010-09-20 Thread Gunnar Wolf
Matt Taggart dijo [Mon, Sep 20, 2010 at 11:22:51AM -0700]: > IMO it's a security bug, but downgrade if you disagree. > > Thanks, I tend to disagree - And it is a characteristic I really appreciate about Debian's packaging of Drupal: One of those great instances of "Install. It just works." that d

Bug#565738: drupal: shouldn't enable on all sites by default

2010-09-20 Thread Matt Taggart
> Matt, > can you please explain why you think this bug is 'grave' and not just = > 'important'? > > To me, grave definition is: > > makes the package in question unusable or mostly so, or causes data > loss, or introduces a security hole allowing access to the accounts of > users who use the pac

Bug#565738: drupal: shouldn't enable on all sites by default

2010-09-20 Thread Luigi Gangitano
Matt, can you please explain why you think this bug is 'grave' and not just 'important'? To me, grave definition is: makes the package in question unusable or mostly so, or causes data loss, or introduces a security hole allowing access to the accounts of users who use the package and I canno

Bug#565738: drupal: shouldn't enable on all sites by default

2010-09-19 Thread Matt Taggart
The original submitter of #565738 is correct, drupal shouldn't enable for all sites on the server by default. It's not enough that "it won't show anything under a domain for which it hasn't been configured", it still allows access and reveals things that shouldn't be by serving the "site off-lin