[pmwiki-users] [pmwiki-devel] Security issues: Disabling action=source & action=diff?

Patrick R. Michaud pmichaud at pobox.com
Wed Dec 6 10:34:44 CST 2006


On Tue, Dec 05, 2006 at 03:58:51PM -0600, Tegan Dowling wrote:
> > What do you mean by a source view for the diff?  You mean
> > "n=Group.Name?action=diff&action=source" together?  But if so, when
> > the source is blocked, it would be blocked for this as well.  Correct?
> 
> On a History page (?action=diff), click the "Show changes to markup"
> link.  This appends ?action=diff&source=y.  Dunno if &source=y draws
> on the same permissions as ?action=source.  You could test it.

The source=y option to ?action=diff still relies on the diff 
permissions.

Pm




More information about the pmwiki-users mailing list