cocoon-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Stefano Mazzocchi <stef...@apache.org>
Subject Re: config question (Cocoon 1.7)
Date Tue, 29 Feb 2000 13:57:37 GMT
Ross Burton wrote:
> 
> > BTW I read your mail about your problem with the ./repository file.
> > What I did was changing the path in my  cocoon.properties file like this:
> >
> > processor.xsp.repository = /usr/local/apache/xsp/repository
> >
> > and than I created the directory with these rights:
> >
> > drwxr-xr-x   2 nobody   nogroup      1024 Feb 28 23:40
> > /usr/local/apache/xsp/repository/
> >
> > And that is just working fine for me.
> > I hope the rights I gave to this directory are not a savety hole if
> > someone knows I would appreciate it.
> 
> I'm not qualified to reply to this fully (Ben Laurie - can we have your
> professional opinion?  :-)  but:

I'm not qualified to answer the question from an Apache point of view,
but...

> * other read/access should be off (drwxr-x---) because then somebody could
> login and read the files.

right, maybe restrict this to the owner and you're even safer.

> * Then as it is owned by nobody/nogroup (which I assume Apache runs as) no
> other processes can access it.

right.

> * It looks like the xsp directory is outside your document root (which is
> probably /usr/local/apache/htdocs) so web users can't access the directory
> 
> Seems okay to me, once the world access rights have been removed for
> completeness.

Yup, ok to me too.

-- 
Stefano Mazzocchi      One must still have chaos in oneself to be
                          able to give birth to a dancing star.
<stefano@apache.org>                             Friedrich Nietzsche
--------------------------------------------------------------------
 Come to the first official Apache Software Foundation Conference!  
------------------------- http://ApacheCon.Com ---------------------



Mime
View raw message