Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 25687 - net-analyzer/cacti will be installed with apache write permissions
Summary: net-analyzer/cacti will be installed with apache write permissions
Status: RESOLVED LATER
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: x86 Linux
: High normal (vote)
Assignee: PHP Bugs
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-08-01 01:23 UTC by MrSpock
Modified: 2003-10-04 05:32 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description MrSpock 2003-08-01 01:23:36 UTC
During install of net-analyzer/cacti-0.8.2a (it is also existent in previous 
versions) the whole directory of cacti will be assigned to the apache owner 
and group. This could allow a remote user to modify or add files in this 
directory.
I see no need in this.
A better approach would be a cacti system user to own these files by default. 
Run the 'php cmd.php' in his crontab.

Furthermore add a symbolic link in /etc/cacti/config.php to 
<cacti_home>/include/config.php (like phpmyadmin does)

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 SpanKY gentoo-dev 2003-08-03 14:39:43 UTC
i changed this once (Bug 20686) ...

php guys, what do you think ?
Comment 2 Stuart Herbert (RETIRED) gentoo-dev 2003-08-03 15:37:01 UTC
It's a web app, right?  For now, it's directories should be owned by the apache 
user, until we've made more progress on the webapps eclass. 
 
Definitely don't think it should have its own user.   However, the idea of having a 
'webapps' user so that apache can only access the files read-only even if cracked 
is a good one. 
 
What's wrong with installing it and making the directories read-only? 
 
Best regards, 
Stu 
Comment 3 Nikl 2003-08-23 17:17:15 UTC
please don't forget adding the at least a comment on the crontab or mentioning the official install docs (http://www.raxnet.net/products/cacti/docs/INSTALL.htm), if you don't have decided on the user issue.

thx,

 - Nikl
Comment 4 solar (RETIRED) gentoo-dev 2003-08-28 21:57:41 UTC
Off topic but..

cacti 0.8.3 released (Development branch)

The changes in this release are as follows:
This version focuses on numerous bugfixes and several feature
enhancements. Some of the features include bandwidth summation, the
ability to add hosts to graph trees, a new DHTML-based tree view, and
a new overall look. The c-based poller (cactid) has been heavily
modified to be more efficient and reliable.  
Comment 5 Stuart Herbert (RETIRED) gentoo-dev 2003-10-04 05:32:29 UTC
We'll be able to fix this more easily once the new web-app tools are done.
 Suggest re-visiting this bug then.

I've marked this as LATER.  We *will* come back to this as soon as possible.

Best regards,
stu