Re: [gbd-dev] Multi-user Debugging on Linux Server
Status: Beta
Brought to you by:
mccabe
From: Linus M. <Li...@mc...> - 2005-06-26 06:28:50
|
Perhaps then we should have two setting files, global and user. In the global setting file you can set defaults and here we could also have settings like: * allow remote debuggers - ie non localhosts * show developer help - which enables/disables the debug subdir * allow port/host on request * Also default host and port could be specified here. In the user settings files (which probably shouldnt be php files then, but normal config files) only host and port can be overridden. Is this a good compromise? /linus On Sunday 26 June 2005 01.12, Brett Serkez wrote: > After reading both posts, I can see the difficulities of both security > and implementation. > > I agree that what ever is done, must be secure or gubed will not be > used. > > As a thought, we could optionally restrict the DebugServer to > 'localhost'. When this restriction is in place, any individuals needing > to debug need to either log on and start the debugger locally or run > secure shell as previously described to create a local port to bring the > session back to their local system. This would give the local system > administrator strict control over who could debug, but not what they > could debug. > > On this second point, seems to me that StartSession.php (soft-link or > real) must exist at or below the directory to be debugged, while this > doesn't control who can debug what, it does limit what can be debugged > control by existing access to the host's directory structure. > > I favor allowing specification of ports on the url for maximum > flexibility, presuming the security issue is resolved. > > Brett > > ------------------------------------- > Brett C. Serkez, Technical Trainer > > > > ------------------------------------------------------- > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > from IBM. Find simple to follow Roadmaps, straightforward articles, > informative Webcasts and more! Get everything you need to get up to > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > _______________________________________________ > Gubed-devel mailing list > Gub...@li... > https://lists.sourceforge.net/lists/listinfo/gubed-devel |