Problems? Is your data what you think it is? | |
PerlMonks |
Re: privilege elevationby BronzeWing (Monk) |
on Jan 21, 2003 at 03:01 UTC ( [id://228564]=note: print w/replies, xml ) | Need Help?? |
Hmm. You said "I don't want to shoehorn all users into the same group and then give the configuration files group priveleges", but perhaps it would be acceptable if you made only the configuration files writable by a certain group, whatever group your CGI is running as (nobody probably). Also I believe you could even sgid that particular CGI into its own group, so that other CGIs wouldn't share its rights to the config files. I still agree with the first comment as the most secure, but I know users usually hate being forced to "waste their time" doing "silly little things" like copying config files when you could make their lives so much easier by just turning down the security a little... I guess it depends on what balance you want between security and ease of use. :p -BronzeWing
In Section
Seekers of Perl Wisdom
|
|