[HCoop-Discuss] SVN security issues

Karl Chen quarl at cs.berkeley.edu
Wed Nov 8 03:49:09 EST 2006


>>>>> On 2006-11-07 13:40 PST, Max Bowsher writes:

    Max> I do not understand why a solution based on sudo forces
    Max> root ownership.

    Max> IIRC, the problem scenario is that www-data needs to run
    Max> hooks under the UID of a human user? 

Almost.  If the problem were that the user wants to run the hook
under his user account, the problem could be solved with sudo.

That is a problem, but a bigger problem is that the administrator
does not want to allow the user to run it under the apache user
account (www-data) even if the user wants to.

-- 
Karl 2006-11-08 00:47




More information about the HCoop-Discuss mailing list