Re: extensive rework of clientside user access rules Re: Syntax of user access rules?

Jan-Oliver Wagner <[email protected]> Fri, 12 Nov 2004 11:09:13 +0100
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
On Fri, Nov 12, 2004 at 10:28:51AM +0100, Renaud Deraison wrote:
> On Thu, Nov 11, 2004 at 12:33:21PM +0100, Jan-Oliver Wagner wrote:
> > What I did is:
> [..]
> 
> That sounds really good - I'll test it ASAP.

feedback very welcome :-) !

> [...]
> > Currently the server side server rules are not retrievable
> > via the protocol. So the user has no full transarency
> > about all rules yet.
> 
> Keeping the rules secrets might also be a good thing. But for the admin
> user, it makes sense, I'll add that to my TODO list.

maybe even make it serverside configurable whether a normaler user
is allowed to see the overall rules or whether not. I can imagine
scenarions where both, transparency and non-transparency, makes sense.

	Jan

-- 
Jan-Oliver Wagner               http://intevation.de/~jan/

Intevation GmbH                      http://intevation.de/
FreeGIS                                http://freegis.org/
_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel