Tags:
create new tag
, view all tags
If I remember well, a user can overwrite the previous release of a topic by adding a proper cmd=xxx option in the save url.

By repeating the process he/she can remove all the version of a topic.

I suggest to have two different save scripts

  • saveadmin for usage only by a poweruser (htaccess protected)
  • save (without the option) for normal usage

-- AndreaSterbini - 13 Sep 2000

I propose to secure this when we have AuthenticationBasedOnGroups in place.

-- PeterThoeny - 13 Sep 2000

The 01 Dec 2000 production release protects the cmd=xxx option. Only members of the TWikiAdminGroup can issue this command.

-- PeterThoeny - 26 Nov 2000

Topic revision: r4 - 01 Jan 2004 - 11:50:04 - SvenDowideit
 
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback