desktopcouch needs to write .ini files readable only by user

Bug #422243 reported by Eric Casteleijn
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
desktopcouch
Fix Released
Critical
Stuart Langridge
desktopcouch (Ubuntu)
Fix Released
Undecided
Chad Miller

Bug Description

Binary package hint: desktopcouch

Since the couchdb .ini files used by desktopcouch will contain login information we need to make sure they are not readable by any user other than the one the database belongs to.

Related branches

Chad Miller (cmiller)
Changed in desktopcouch (Ubuntu):
status: New → Confirmed
assignee: nobody → Stuart Langridge (sil)
Changed in desktopcouch:
status: New → Confirmed
assignee: nobody → Stuart Langridge (sil)
importance: Undecided → Critical
milestone: none → w25-karmic-finalfreeze
Stuart Langridge (sil)
tags: added: ubuntuone-karmic
Revision history for this message
Chad Miller (cmiller) wrote :

Two things:

1) We should restrict log files also.
2) It would be easier to only chmod the directories that contain them.

Or, just set the umask when we start up. Is there anything we make with desktopcouch that should be readable by other people?

Revision history for this message
Stuart Langridge (sil) wrote :

Set folders to 0770, files to 0660.

Changed in desktopcouch (Ubuntu):
status: Confirmed → In Progress
Changed in desktopcouch:
status: Confirmed → In Progress
Revision history for this message
Stuart Langridge (sil) wrote :

Assigned specifically-Ubuntu bug to chad since it's to do with packaging

Changed in desktopcouch:
status: In Progress → Fix Committed
Changed in desktopcouch (Ubuntu):
assignee: Stuart Langridge (sil) → Chad Miller (cmiller)
Stuart Langridge (sil)
Changed in desktopcouch:
status: Fix Committed → Fix Released
Chad Miller (cmiller)
Changed in desktopcouch (Ubuntu):
status: In Progress → Fix Committed
Elliot Murphy (statik)
Changed in desktopcouch (Ubuntu):
status: Fix Committed → Fix Released
Chad Miller (cmiller)
Changed in desktopcouch:
status: Fix Released → Fix Committed
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.