[Typo3-dev] Patch to make the EM work with suphp

Michael Stucki michael at typo3.org
Tue Dec 20 16:40:41 CET 2005


Martin Kutschker wrote:

>> In my case, I have created a new group "webeditors" instead. So the first
>> thing I do after setting up a new site is to append the createGroup
>> setting in localconf.php.
> 
> So? The point is, the group may write.

Yes, these are the steps I do if I want to have a group that gets write
permission for those files.

>> I think it is better to change it. I agree that you will not gain a lot
>> of security with this, but still it is more safe and it won't touch a lot
>> of users I guess.
> 
> How can you write to those files if the permission deny write access to
> the group? This is, as I understood it, what Oliver wants.

Exactly. By default the files are no longer writable for the group unless
you manually changed the fileCreateMask. While doing this, it is an easy
step to also change the createGroup setting.

The point is that unless you know which group you give write access (applies
to most of all cases), the setting should be disabled.

Please give me a good reason to not change it besides that you seem to be
too lazy to set it manually :-)

- michael
-- 
Use a newsreader! Check out
http://typo3.org/community/mailing-lists/use-a-news-reader/




More information about the TYPO3-dev mailing list