Web Images Videos Maps News Shopping Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
ApplicationFileOrganizationSec urityConcerns on the wiki
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  6 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Matt Osbun  
View profile  
 More options Jun 29, 3:37 pm
From: Matt Osbun <mos...@gmail.com>
Date: Mon, 29 Jun 2009 15:37:29 -0400
Local: Mon, Jun 29 2009 3:37 pm
Subject: ApplicationFileOrganizationSecurityConce rns on the wiki

While going through the Mach-II doc wiki, I noticed that the followinh page
is blank:
http://greatbiztoolsllc.trac.cvsdude.com/mach-ii/wiki/ApplicationFile...

Was the intention behind this page to address preventing people from
downloading the Mach-II xml config file through a browser request?

Reason I ask is because I've spend the last couple of hours working with
this issue, and could fill the page out with some ideas. However, given my
track record for assuming things today, I'm also doublechecking gravity
before sitting down. It's been one of those Mondays.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Peter J. Farrell  
View profile  
 More options Jun 29, 3:50 pm
From: "Peter J. Farrell" <pe...@mach-ii.com>
Date: Mon, 29 Jun 2009 14:50:25 -0500
Local: Mon, Jun 29 2009 3:50 pm
Subject: Re: [Mach-II] ApplicationFileOrganizationSecurityConce rns on the wiki

Yeah, the link title is:

Addressing Application File Organization and Security Concerns?
<http://greatbiztoolsllc.trac.cvsdude.com/mach-ii/wiki/ApplicationFile...>

So I think Matt was thinking about how file organization can affect
security.  There are two approaches -- the one you outline with
everything off one directory and the other method where you have an
public_html folder which is the webroot and everything else is above
webroot and therefore web-inaccessible>

|-+ YourApplicationName
  |- config
  |- modules
  |  |- ModuleName
  |  |  |- config
  |- public_html
  |- ... additional folders ...

There is also some information here:
http://greatbiztoolsllc.trac.cvsdude.com/mach-ii/wiki/FAQRecommendedC...

Go ahead and go nuts on an article.  The great thing is that wiki is
publicly accessible and editable -- so it can get revised / updated /
improved, but none of that can happen until there is something to edit.  
So yes, add information to that stub!

Best,
Peter

Matt Osbun said the following on 06/29/2009 02:37 PM:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Matthew Woodward  
View profile  
 More options Jun 29, 3:49 pm
From: Matthew Woodward <m...@mattwoodward.com>
Date: Mon, 29 Jun 2009 12:49:26 -0700
Local: Mon, Jun 29 2009 3:49 pm
Subject: Re: [Mach-II] ApplicationFileOrganizationSecurityConce rns on the wiki

Matt Osbun wrote:
> While going through the Mach-II doc wiki, I noticed that the followinh
> page is blank:
> http://greatbiztoolsllc.trac.cvsdude.com/mach-ii/wiki/ApplicationFile...

> Was the intention behind this page to address preventing people from
> downloading the Mach-II xml config file through a browser request?

Yep, I think maybe I stubbed that out as a reminder that needed to be
addressed. It would be GREAT if you wanted to slap some stuff in there.
That would be much appreciated.

The two main approaches are:

* Put the file somewhere that's accessible to your CFML engine but not
browsable

* Add .cfm at the end of the file name (mach-ii.xml.cfm) and put <!--
<cfsetting enablecfoutputonly="true" /> --> at the top of the file

But if you have other ideas feel free to share here or put them in the
wiki. Thanks!
--
Matthew Woodward
m...@mattwoodward.com
http://www.mattwoodward.com/blog

Please do not send me proprietary file formats such as Word, PowerPoint,
etc. as attachments.
http://www.gnu.org/philosophy/no-word-attachments.html

  smime.p7s
4K Download

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Matthew Woodward  
View profile  
 More options Jun 29, 4:06 pm
From: Matthew Woodward <m...@mattwoodward.com>
Date: Mon, 29 Jun 2009 13:06:01 -0700
Local: Mon, Jun 29 2009 4:06 pm
Subject: Re: [Mach-II] Re: ApplicationFileOrganizationSecurityConce rns on the wiki

Matthew Woodward wrote:
> Matt Osbun wrote:
>> Was the intention behind this page to address preventing people from
>> downloading the Mach-II xml config file through a browser request?

Peter's answer is more all-encompassing since we do (I believe) have
another FAQ about the config file, but if you want to put your
experiences concerning that in that article to start, that would be great.
--
Matthew Woodward
m...@mattwoodward.com
http://www.mattwoodward.com/blog

Please do not send me proprietary file formats such as Word, PowerPoint,
etc. as attachments.
http://www.gnu.org/philosophy/no-word-attachments.html

  smime.p7s
4K Download

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Matt Osbun  
View profile  
 More options Jun 30, 9:01 am
From: Matt Osbun <mos...@gmail.com>
Date: Tue, 30 Jun 2009 09:01:06 -0400
Local: Tues, Jun 30 2009 9:01 am
Subject: Re: [Mach-II] Re: ApplicationFileOrganizationSecurityConce rns on the wiki

Got some initial thoughts on the wiki. Could probably use some expanding,
but it gets some ideas across, I think.

On Mon, Jun 29, 2009 at 3:50 PM, Peter J. Farrell <pe...@mach-ii.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Matthew Woodward  
View profile  
 More options Jun 30, 9:17 am
From: Matthew Woodward <m...@mattwoodward.com>
Date: Tue, 30 Jun 2009 06:17:15 -0700
Local: Tues, Jun 30 2009 9:17 am
Subject: Re: [Mach-II] Re: ApplicationFileOrganizationSecurityConce rns on the wiki

Matt Osbun wrote:
> Got some initial thoughts on the wiki. Could probably use some
> expanding, but it gets some ideas across, I think.

Thanks Matt! Greatly appreciated.

--
Matthew Woodward
m...@mattwoodward.com
http://www.mattwoodward.com/blog

Please do not send me proprietary file formats such as Word, PowerPoint,
etc. as attachments.
http://www.gnu.org/philosophy/no-word-attachments.html

  smime.p7s
4K Download

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google