#15 Ability to delete root File Manage directory

0.9.1
closed-fixed
nobody
Security (23)
8
2005-05-25
2005-05-25
Brandon Nimon
No

I was messing around with the console and tried a
"rmdir /" which worked. This command deleted everything
in the directory (lukily it was just a test directory),
but if the console can delete the main directory a the
UI can too (if you know what you are doing).

The ability for an admin to delete the main directory
isn't nearly as bad as any user with ddelete
permissions having the ability to do so.

I will fix this before the day is out.

Discussion

  • Brandon Nimon
    Brandon Nimon
    2005-05-25

    Logged In: YES
    user_id=1049916

    And release 0.9.1 before the day is out.

     
  • Brandon Nimon
    Brandon Nimon
    2005-05-25

    • status: open --> open-accepted
     
  • Brandon Nimon
    Brandon Nimon
    2005-05-25

    • status: open-accepted --> closed-fixed
     
  • Brandon Nimon
    Brandon Nimon
    2005-05-25

    Logged In: YES
    user_id=1049916

    fixed. Added a test against "/". 0.9.1 is rereleased.

    Now users cannot rename or get properties of the root
    directory also.