Bug#308001: munin: should not store web application data in /var/www

2005-05-15 Thread Marc Haber
Hi, On Tue, May 10, 2005 at 11:21:19AM +0200, Tore Anderson wrote: * Marc Haber I think the reality is in between these examples. But, there might be insightful discussion on debian-devel. I was just told that there's actually a recently started (good timing, eh?) project that aims

Bug#308001: munin: should not store web application data in /var/www

2005-05-15 Thread Tore Anderson
* Marc Haber I had actually hoped to get away without having to subscribe to yet another mailing list, and I am not too happy with their idea of using CVS as a collaboration medium instead of a more modern wiki. Developing documents using text input forms in a web browser? Yuck! That's

Bug#308001: munin: should not store web application data in /var/www

2005-05-10 Thread Tore Anderson
* Marc Haber I think the reality is in between these examples. But, there might be insightful discussion on debian-devel. I was just told that there's actually a recently started (good timing, eh?) project that aims to create a brand new policy for webapps, see

Bug#308001: munin: should not store web application data in /var/www

2005-05-09 Thread Tore Anderson
* Marc Haber [this should probably be a policy violation and thus serious] No, like #308008 it fails the must or required-condition. Policy 11.5 says Web Application shold try to avoid storing fils in the Web Document Root. Since, however, munin's web pages are generated and not included

Bug#308001: munin: should not store web application data in /var/www

2005-05-09 Thread Marc Haber
Hi Tore, On Mon, May 09, 2005 at 08:18:00AM +0200, Tore Anderson wrote: I'm a bit uncertain here. A quick apt-file search -x \^var/www show 60 packages containing the /var/www directory, including packages similar to Munin (cricket and mrtg). For some reason, Munin itself didn't show

Bug#308001: munin: should not store web application data in /var/www

2005-05-09 Thread Tore Anderson
tags 308001 moreinfo quit * Marc Haber torrus is an example of the other kind. I remember not liking the cricket packaging at all, and mrtg is probably not a very good example. I'm not so sure if I like the torrus packaging, with one binary package per httpd. 19 packages is providing

Bug#308001: munin: should not store web application data in /var/www

2005-05-09 Thread Marc Haber
On Mon, May 09, 2005 at 01:11:18PM +0200, Tore Anderson wrote: * Marc Haber torrus is an example of the other kind. I remember not liking the cricket packaging at all, and mrtg is probably not a very good example. I'm not so sure if I like the torrus packaging, with one binary

Bug#308001: munin: should not store web application data in /var/www

2005-05-07 Thread Marc Haber
Package: munin Version: 1.2.3-1 Severity: normal [this should probably be a policy violation and thus serious] Hi, Policy 11.5 says Web Application shold try to avoid storing fils in the Web Document Root. Since, however, munin's web pages are generated and not included in the package, they