Re: [Tiki-devel] Security, Extra Smarty functions, Extra Smarty modifiers, Extra Smarty directories are gone ?

Bsfez Tiki via TikiWiki-devel <[email protected]>
Newsgroups gmane.comp.cms.tiki.devel
Message-ID <[email protected]>
Aoutch… The explanation on the page seems to be problematic once moved on a real server.

I created a tiki.ini file and I have now a warning when going to admin control panels:

 Warning
Tiki detected system configuration files with .ini extension, under the root folder of Tiki. It is recommended to change it to .ini.php.
Check https://doc.tiki.org/System-Configuration for examples.

Renaming my file and adding more information to both docs later.

Bernard


> On 16 Feb 2021, at 13:24 , Bsfez Tiki via TikiWiki-devel <[email protected]> wrote:
> 
> A few weeks later…
> 
> While I rarely change such settings and I understand why risky stuff should be hidden (may be more than everyone here 😂) I have the feeling it has been done based on individual usage and not really for any "Expert/" of the Tiki community.
> Not every admin use Tiki with configuration files, parameters in local.php or tiki.ini.
> The Doc is thin.
> 
> 
> It should have been optional.
> 
> We could have reused other simpler mechanism we use on other places.
> For example the "Enter admin password" double authentication like to assign a user to a group.
> 
> "You are about to save a risky thing, please enter your admin password to confirm… bla bla".
> 
> 
> I added some information on the documentation page to help others: https://doc.tiki.org/Risky-Preferences
> 
> Bernard
> 
> 
>> On 26 Jan 2021, at 17:20 , [email protected] wrote:
>> 
>> Below
>> 
>> 
>> On Tue, 26 Jan 2021 08:53:44 +0200 Tiki developers [email protected] said
>> 
>>> I see… (thanks Marc) While I understand the reasons and don’t really have an opinion on this
>>> yet, I think the tooltip should be then adapted to the new situation so
>>> people knows where to look. At tiki-admin.php?page=security Smarty security Under the I (information) Tooltip : Do not allow PHP code in Smarty
>>> templates. To : Do not allow PHP code in Smarty templates. Specific settings can be
>>> overridden and modifiers or functions added by the system administrator
>>> through Tiki's system configuration file. Then the link would go to :  https://doc.tiki.org/Risky-Preferences 
>> 
>> This is how to add a help link:
>> http://dev.tiki.org/Create-a-new-preference#help
>> 
>> But https://doc.tiki.org/Risky-Preferences is a different concept.
>> 
>> There should be another page.
>> 
>> 
>>> Bernard On 26 Jan 2021, at 04:55 , [email protected] wrote: https://doc.tiki.org/Risky-Preferences On Mon, 25 Jan 2021 18:01:53 +0200 Tiki developers
>>> [email protected] said Hello, On Tiki 22 I can’t find the Extra Smarty functions, Extra Smarty
>>> modifiers, Extra Smarty directories fields on the security control panel  By the look
>>> of the code I have doubt it was voluntary… Was it ? Bernard _______________________________________________ TikiWiki-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
>> 
>> 
>> 
>> 
>> _______________________________________________
>> TikiWiki-devel mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
> 
> 
> 
> _______________________________________________
> TikiWiki-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel



_______________________________________________
TikiWiki-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.