DokuWiki

It's better when it's simple

User Tools

Site Tools


plugin:phprestrict

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
plugin:phprestrict [2016-09-14 15:04]
81.67.68.4 [Discussion]
plugin:phprestrict [2018-05-28 21:41] (current)
Klap-in [Installation]
Line 6: Line 6:
 email      : trebor@animeigo.com ​ email      : trebor@animeigo.com ​
 type       : action type       : action
-lastupdate : 2016-06-07 +lastupdate : 2016-11-23 
-compatible : 2016-06-26, Detritus+compatible : 2016-06-26, 2017-03-04, Detritus, Elenor of Tsort, Frusterick Manners
 depends ​   :  depends ​   : 
 conflicts ​ :  conflicts ​ : 
Line 20: Line 20:
 ===== Installation ===== ===== Installation =====
  
-Install ​the plugin using the [[plugin:plugin|Plugin ​Manager]] ​and the download URL above, which points to latest version of the plugin. Refer to [[:​Plugins]] on how to install plugins manually.+Search and install ​the plugin using the [[plugin:extension|Extension ​Manager]]. Refer to [[:​Plugins]] on how to install plugins manually.
  
 ===== Examples/​Usage ===== ===== Examples/​Usage =====
Line 44: Line 44:
   * **2016-06-07**   * **2016-06-07**
     * 1.1; minor cleanups, added disabling of revision history. Fixed problem with extra level of folder nesting in the GIT repository (newbie mistake)     * 1.1; minor cleanups, added disabling of revision history. Fixed problem with extra level of folder nesting in the GIT repository (newbie mistake)
 +  * **2016-11-23** 
 +    * Pointfix: Disabled execution of <PHP> content on history pages (which would permit execution of old/​obsolete code if the history pages were visible or the history page url was known).
 ===== FAQ ===== ===== FAQ =====
 +===== Forum ===== 
 +  * [[https://​forum.dokuwiki.org/​thread/​13734|English : Working on PHPrestrict plugin - have some questions]] 
 +  * [[https://​forum.dokuwiki.org/​thread/​14044|Français : [PLUG-IN PHPRESTRICT] - Utilisation ]]
  
 ===== Discussion ===== ===== Discussion =====
Line 57: Line 60:
 2016-09-14 (MadOverlord) : I don't know if is possible, and it is a bit out of scope. The whole point of the plugin is that it lets you restrict who can use PHP by specifying where PHP is allowed and then using the ACL to restrict who can edit those pages. If you let a bad-actor have access to PHP, having them be able to execute phpinfo(); is the least of your problems! 2016-09-14 (MadOverlord) : I don't know if is possible, and it is a bit out of scope. The whole point of the plugin is that it lets you restrict who can use PHP by specifying where PHP is allowed and then using the ACL to restrict who can edit those pages. If you let a bad-actor have access to PHP, having them be able to execute phpinfo(); is the least of your problems!
  
-2016-09-14 (Wild Dagger) : Thank you for the quick response, how can we help to translate the plug-in?+2016-09-14 (Wild Dagger) : Thank you for the quick response, how can we help you to translate the plug-in? 
 + 
 +2016-09-14 (MadOverlord) : I do not understand what you mean by '​translate the plug-in'​. You will have to be more explicit. All the code is available in the plugin download and on github: https://​github.com/​RJWoodhead/​dokuwiki-plugin-phprestrict 
 + 
 +2016-09-14 (Wild Dagger) : [[https://​github.com/​RJWoodhead/​dokuwiki-plugin-phprestrict/​tree/​master/​lang/​en|/​lang/​en]]/​settings.php or more to other language. 
 + 
 +2016-09-14 (MadOverlord) : If you wish to add support in the settings for another language, just submit a pull request to add a land/​xx/​settings.php file 
 + 
 +2016-09-14 (Wild Dagger) : Thank you MadOverlord :) What do you mean about "​Disable __view__/​__export__/​__revisions__ on PHP-enabled pages" ? 
 + 
 +When i enable the option (in Release 2016-06-26a "​Elenor of Tsort" with default template) : 
 + 
 +  * A simple user with Read permission (ACL): 
 +    * ?​do=export_raw -> Command disabled: export_raw 
 +    * ?​export_xhtml -> works (does not show the php code) 
 +    * ?​do=export_xhtml -> works (does not show the php code) 
 +    * ?​export_xhtmlbody -> works (does not show the php code) 
 +    * ?​do=export_xhtmlbody -> works (does not show the php code) 
 +    * ?do=edit -> **__works__** (__show the source code__) 
 +    * I have not tested the revised options 
 + 
 +2016-09-14 (MadOverlord) Wild Dagger : I believe you may have given the user additional permissions. For the default (non-logged in user) with read access, when I try ?do=edit, I get "​Command disabled: source"​. If the user is granted edit access, he can obviously edit the page and see the source -- that is intended. 
 + 
 +2016-09-14 (Wild Dagger) Thank you for all these details, I'll enable 'View source'​ in '​Actions to disable in DokuWiki'​ for my closed dokuwiki ;-) and if I understand the option "​Disable view / export / revisions on PHP-enabled pages?"​ in your plug-in is only for public dokuwiki (no register). Good plug-in but I think that some users would like to see the sources (excluding php pages) in closed dokuwiki. ( not me ;-) ) 
plugin/phprestrict.1473858258.txt.gz · Last modified: 2016-09-14 15:04 by 81.67.68.4