Re: [gbd-dev] Multi-user Debugging on Linux Server
Status: Beta
Brought to you by:
mccabe
From: Brett S. <tec...@se...> - 2005-06-26 15:49:04
|
> Sounds pretty good to me. Any insecure functionality could be disabled by > default and hopefully only enabled in a secure environment. The > documentation could warn the user of the risks of enabling the > functionality and advise what security measures should be in place. Agreed. Presumably there will also be warning comments in the configuration file? > Will we be getting rid of the localsettings file parameter? One of the > things I like about it is that it allows a user to have simultaneous > debug sessions and allows multiple projects to be debugged at the same > time but independently. I could go either way on this. I would advocate keeping the localsettings file parameter. I would still advocate for optionally allowing the DebugPort to be specified on the url for maximum flexibility. If the default will be to only allow connections to the local host, then in order for this to be exploited, the user would have to have a away to establish the socket on the local system. In the case of multiple debug sessions, without specifying the DebugPort on the URL, the localsettings file would need to be edited or copied. Brett ------------------------------------- Brett C. Serkez, Technical Trainer |