maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Community (https://talk.maemo.org/forumdisplay.php?f=16)
-   -   Unauthorised editing (https://talk.maemo.org/showthread.php?t=32484)

EIPI 2009-10-08 11:33

Re: Unauthorised editing
 
I can confirm that I have made an edit to the Summit Accomodations wiki page without being logged in - I think it logged my IP. A serious security hole.

bergie 2009-10-08 11:50

Re: Unauthorised editing
 
Quote:

Originally Posted by qole (Post 340494)
That is very interesting and disturbing... Someone made it into a page of spam links. There's a security hole in Midgard, methinks.

That area used to be publicly editable, and so I assume some leftover permission set there. So not really a security hole, just setting put there by site admins.

Edit: checked the editing page, and anon users correctly get Access denied: You need the privilege midgard:update. Maybe somebody already changed the permissions of that area

bergie 2009-10-08 11:58

Re: Unauthorised editing
 
Quote:

Originally Posted by TA-t3 (Post 340513)
The Midgard wiki is a bit unusual. When logged in there'll be a hovering menu up in the bar and you can move the cursor over the one that says 'Page'[1] to get to the edit menu.

I'm not particularly fond of it - it's quite different from other wikis

Yes, the "floating toolbar" that appeared in MidCOM 2.6 is more oriented towards typical CMS scenarios where you want editing tools to not disturb the general site layout.

It is however not the only way to present toolbars in Midgard, just the default. We could draw them inside the page, or even in the navigation like is done in wiki.maemo.org. Come and talk with me in the summit and we can discuss what way to change it :cool:

Zelig87 2009-10-10 11:07

Re: Unauthorised editing
 
You needed a certain level of Karma to vote in the Community Council elections.

Not sure if it is possible, but perhaps editing pages should require a similar level of Karma.

qole 2009-10-15 19:41

Re: Unauthorised editing
 
bergie: I didn't see your note before/during the Summit. But I would really like the Midgard menu made non-floating. It doesn't work in the Fremantle browser, for one thing, and it isn't very intuitive, for another.


All times are GMT. The time now is 23:39.

vBulletin® Version 3.8.8