Re: [Tiki-devel] Security, Extra Smarty functions, Extra Smarty modifiers, Extra Smarty directories are gone ?
Bsfez Tiki via TikiWiki-devel <[email protected]>
| Newsgroups | gmane.comp.cms.tiki.devel |
|---|---|
| Message-ID | <[email protected]> |
Aoutch… The explanation on the page seems to be problematic once moved on a real server. I created a tiki.ini file and I have now a warning when going to admin control panels: Warning Tiki detected system configuration files with .ini extension, under the root folder of Tiki. It is recommended to change it to .ini.php. Check https://doc.tiki.org/System-Configuration for examples. Renaming my file and adding more information to both docs later. Bernard > On 16 Feb 2021, at 13:24 , Bsfez Tiki via TikiWiki-devel <[email protected]> wrote: > > A few weeks later… > > While I rarely change such settings and I understand why risky stuff should be hidden (may be more than everyone here 😂) I have the feeling it has been done based on individual usage and not really for any "Expert/" of the Tiki community. > Not every admin use Tiki with configuration files, parameters in local.php or tiki.ini. > The Doc is thin. > > > It should have been optional. > > We could have reused other simpler mechanism we use on other places. > For example the "Enter admin password" double authentication like to assign a user to a group. > > "You are about to save a risky thing, please enter your admin password to confirm… bla bla". > > > I added some information on the documentation page to help others: https://doc.tiki.org/Risky-Preferences > > Bernard > > >> On 26 Jan 2021, at 17:20 , [email protected] wrote: >> >> Below >> >> >> On Tue, 26 Jan 2021 08:53:44 +0200 Tiki developers [email protected] said >> >>> I see… (thanks Marc) While I understand the reasons and don’t really have an opinion on this >>> yet, I think the tooltip should be then adapted to the new situation so >>> people knows where to look. At tiki-admin.php?page=security Smarty security Under the I (information) Tooltip : Do not allow PHP code in Smarty >>> templates. To : Do not allow PHP code in Smarty templates. Specific settings can be >>> overridden and modifiers or functions added by the system administrator >>> through Tiki's system configuration file. Then the link would go to : https://doc.tiki.org/Risky-Preferences >> >> This is how to add a help link: >> http://dev.tiki.org/Create-a-new-preference#help >> >> But https://doc.tiki.org/Risky-Preferences is a different concept. >> >> There should be another page. >> >> >>> Bernard On 26 Jan 2021, at 04:55 , [email protected] wrote: https://doc.tiki.org/Risky-Preferences On Mon, 25 Jan 2021 18:01:53 +0200 Tiki developers >>> [email protected] said Hello, On Tiki 22 I can’t find the Extra Smarty functions, Extra Smarty >>> modifiers, Extra Smarty directories fields on the security control panel By the look >>> of the code I have doubt it was voluntary… Was it ? Bernard _______________________________________________ TikiWiki-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel >> >> >> >> >> _______________________________________________ >> TikiWiki-devel mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel > > > > _______________________________________________ > TikiWiki-devel mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel _______________________________________________ TikiWiki-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel