Hi Hans-Juergen,
Hans-Juergen Tappe schrieb:
Hi!
OK, I thought a bit more about this:
A) The “don’t ask if webdav.php accesses a o+r mode file in a o+x
directory tree” approach:
–> May not work with multiple domains because the login distinguishes
which file tree to look into. (Is this true or is there a domain=
parameter?)
It depends on the installation, if the instance is selected from the
domain used in the url or from the login name. Recommended is definitely
the first (instance name match domain name of url).
B) The general solution for a public directory in the web server:
–> Skip this, it’s a security issue.
–> We do need a public storage within the filemanager, accessible
through a pipe in webdav.php.
C) The sitemgr download module
–> If there should be a public access to the filemanager, a website
needs to be setup, which passes the correct credentials parameter to
the webdav.php. I will go and add this option to the download module.
Ok
–> If a plain HTML mail template wants to access images on this public
folder, it will need to use the credentials as given in the sitemgr
download module (to be implemented).
Ok
–> As the anon user needs access to the filemanager, the setup needs to
take care to retract write permissions on the anon user and group
folders in /home/. Ralf, can you please take care of this?
It’s not that simple. If setup creates
dr-x------ anonymous root /home/anonymous
Anonymous user can give himself the write rights again, as he is the
owner of that directory. I need to implement something in vfs, to not
check owner rights, if user is anonymous.
D) The FCKeditor will need a input module for access to the filemanager
–> For use inside the sitemgr, it should use the same ?auth= mechanism,
such that sending a link to a website image through a mail will work.
This could be implemented by some extra parameter or environment
variable when called from inside a sitemgr module.
The problem might be, that we need both:
- currently implemented way of browsing pictures in directories inside
the docroot and inserting img tag with just the url of picture
- browsing of (anonymous) accessible pictures in vfs and inserting an
img tag with webdav url
The GET parameter auth=… is anyway only used, if there’s not already
a session. So regular access via sitemgr, does NOT need it, as there’s
already a session. Only if you bookmark a download link or mail it to
someone, you need that parameter - thought it does not hurt in the other
cases.
You’re sure you dont want to participate in the project
You should come and visit us at Stylite in Kirchheimbolanden, as you
live just a few km’s away. You are more then welcome, just let me know
in advance, as I’m working from my home office in Kaiserslautern most of
the time.
Ralf
Ralf Becker
Director Software Development
Stylite GmbH
[open style of IT]
Morschheimer Strasse 15
67292 Kirchheimbolanden
fon +49 (0) 6352 70629-0
fax +49 (0) 6352 70629-30
mailto: rb@stylite.de
www.stylite.de
www.egroupware.org
Geschäftsführer Andre Keller, Gudrun Müller,
Nigel Vickers und Ralf Becker
Registergericht Kaiserslautern HRB 30575
Umsatzsteuer-Id / VAT-Id: DE214280951
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what’s new with
Crystal Reports now. http://p.sf.net/sfu/bobj-july
eGroupWare-developers mailing list
eGroupWare-developers@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/egroupware-developers