Security issue with Filemanager

This is an open forum for any mojoPortal topics that don't fall into the other categories.

This thread is closed to new posts. You must sign in to post in the forums.
6/12/2009 7:16:25 AM
Gravatar
Total Posts 14

Security issue with Filemanager

Joe,

Using filemanager shows up the complete physical path beyond the root.
Although it is not possible to navigate above root, it is somehow disclosing information which shouldn't happen.

Is there a way to suppress the information shown in filemanager above the portal's root?

Thanks,

Juerg

6/12/2009 7:36:23 AM
Gravatar
Total Posts 18439

Re: Security issue with Filemanager

Hi Juerg,

I can see why you might like to hide it in a multi site installation where you have multiple customers hosted in the same installation. I will add a config setting to allow you to hide that label for the next mojoPortal release. I generally only host multiple sites for a single customer in one installation so it hasn't been an issue for me, its an administrative feature only available to admins.

Best,

Joe

 

6/12/2009 8:55:57 AM
Gravatar
Total Posts 14

Re: Security issue with Filemanager

Joe,

Thank you, very much appreciated.

As you are saying that filemanager is only an admin feature, would it be possible to add the same security model as it is valid for normal pages to filemanager?

This way, we could make file management selectivly available e.g. to content admins etc.
Obviously, the directory should also be selectable where these guys have acces to.

I can see it as a very basic option in order to make e.g. just one directory (-path) accessible.
It would be used solely for pictures, logos, documents, not the whole cms system as such. This should be reserved for admins.
I thinking for ordinary user who can update content, so they shall be able to manage new documents, drop old ones and so on.

What do you think about such a new feature?
Surely, we could setup a FTP path, but as filemanager is so nicely integrated into the mojo portal I vote for an integration.

Juerg

 

6/12/2009 11:04:04 AM
Gravatar
Total Posts 18439

Re: Security issue with Filemanager

There is nothing currently implemented to give individual users access to individual folders. File Manages is an admin tool, its possible to break the site by deleting a master page from a skin or other things. For user file storage I use the Shared Files module, but its not designed for storing things that will be used within other content.

At some point perhaps I will implement the kind of thing you are talking about but its not there now.

Best,

Joe

You must sign in to post in the forums. This thread is closed to new posts.