Re: parameter actions - a security issue?
Anthony Eden <[email protected]> Tue, 04 Feb 2003 22:50:14 -0500
| Newsgroups | gmane.comp.java.jpublish.devel |
|---|---|
| Message-ID | <[email protected]> |
I have released JPublish 1.4.1 today to address this issue ( available at http://www.jpublish.org/ ). The new release disables parameter actions by default and they can be enabled by adding the following line to your jpublish.xml configuration file: <enable-parameter-actions>true</enable-parameter-actions> Thank you for pointing this out Florian. Sincerely, Anthony Eden Florian Gnägi wrote: > In the jPublish.xml file there is a configuration option > > <action-identifier>action</action-identifier> > > This allows to create URLs like www.bla.com/myfile.mtml?action=doThisAndThatAction > > I consider this feature a very problematic since it gives the user a free ticket to issue every action that is available in the entire system. Let's say you have an action somewhere that is called 'dropMyEntireDatabase' and you have protected the page that uses this action with a path action that checks for security. One would expect to be on the save side, however users will be able to bypass the security and call the actions directly without any preconditions (like the security action that would protect the page or state in a workflow that must be set somewhere else). > > This might not be such a problem in a closed environment, but it definitely is in an open source project where security by obscurity is not possible. One could protect each action by some lines, but this would mess up any nice design with a lot of redundant code. > > Of course, clean design where security is beeing checked on a lower level, eg. within the managers, somehow prevents users from issuing actions like the dropMyEntireDatabase action, but there are still many cases where unexpected stuff could happen. > > Unfortunately it is not possible to turn off this parameter action feature. In my point of view it should be possible to turn it off entirely. As an alternative actions that can be parameter actions should be declared as such explicitely, e.g. by implementing another interface than the default action interface. Right now the only solution I see is to use some cryptic randomly generated action-identifyer, but this is not a real solution. > > What do you mean? Is there a configuration option I haven't seen so far? > > Sincerly > -Florian Gnaegi > > Florian Gnägi <[email protected]> > http://www.olat-zentrum.unizh.ch > > Center for Computing Services > OLAT-Zentrum > University of Zurich Phone: +41 1 63 56788 > Winterthurerstrasse 190 > CH-8057 Zuerich FAX: +41 1 63 54505N¬HSDM隊X¬²š'²ŠÞu¼’¢êÜxZ+á'µêé®+ØÂЉþ >.)îÅj+•âg†)à Ù'ž†Ûiÿü0Âö¬¡ûpj·œ¢bi¹¹b²^½éh¥êæj)bž b²Òi¹¹b²^½éh¥êåŠËl²‹«qçè®§zØm¶›?þX¬¶Ë(º·~Å Ã zwÂþX¦ÃåŠËbú?Ž››–+!uëÞ–Š^r=== ------------------------------------------------------- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com