Bertrand Delacretaz wrote:
> Hi Jukka,
> 
> On Wed, Apr 22, 2009 at 12:25 PM, Jukka Zitting <jukka.zitt...@gmail.com> 
> wrote:
>> ...I was thinking about the implications of giving a user write access to
>> a subtree of the repository. With that access the user could now
>> upload a new script and create a node that invokes that script when
>> rendered....
> 
> Requiring scripts to be stored under /libs or /apps, as a first step
> until we have something better, could help here, as website users are
> not supposed to be able to write to these locations.
> 
I'm not sure if I understand the whole discussion here. But scripts are
only picked
up from configured paths (libs and apps by default). So as long as the
user is not allowed to write in these locations, everything should be fine.

Carsten
-- 
Carsten Ziegeler
cziege...@apache.org

Reply via email to