Windows fails to enforce Security Policies for drives access

Bug #167795 reported by Bug Importer
2
Affects Status Importance Assigned to Milestone
Inkscape
Fix Released
Low
Joelholdsworth

Bug Description

When selecting to open a file, Inkscape allows a user
to see drives that are to be hidden with Windows
Server Group Policies. The software appears to be
using a component that does not follow the security
Microsoft Windows security model. Applications such
as OpenOffice do not have this issue. This issue has
appeared in older psuedo windows applications which
appear to have their own components loading that
interact with the system.

Why would this be important? Let's say you want to
provide terminal server sessions with users having
access to Inkscape for general drawing usage. With
the current security model Inkscape bypasses one of
the nice features setup by the administrator to secure
the server.

Group Policy information:
Administrative Template - Windows Components/Windows
Explorer
Hide these specified drives in "My Computer"
(Restrict A, B, C, D)
Prevent Access to drives from "My Computer"
(Restrict A, B, C)

Tags: build
Revision history for this message
Rwst (rwst) wrote :

you got it all wrong, not inkscape does these things,
inkscape only uses the Gtk+ UI library which does these
things, so please report this upstream with the Gtk+ folks
if you deem this such an important issue.

why Windows wouldn't just hide the hidden files from
applications is beyond me, but then, there appears to be a
pattern with Windows and security.

Revision history for this message
Jon A. Cruz (jon-joncruz) wrote :

Definitely sounds like a major flaw in the "security"
technology of the OS. If applications and accidentally
bypass it, then it doesn't sound like actual security.

This really sounds like it needs to be registered as a bug
with Microsoft.

Revision history for this message
Ulferikson (ulferikson) wrote :

I don't think group policies are meant to be seen as
security settings..

Using Group Policy Objects to hide specified drives
http://support.microsoft.com/kb/231289/EN-US/

"These settings remove the icons representing the selected
hard disks from My Computer, Windows Explorer, and My
Network Places. Also, these drives do not appear in the Open
dialog box of any programs."

"This policy does not prevent users from using other
programs to gain access to local and network drives or
prevent them from viewing and changing drive characteristics
by using the Disk Management snap-in."

Revision history for this message
Bug Importer (bug-importer) wrote :

blub

Revision history for this message
Buliabyak-users (buliabyak-users) wrote :

Originator: NO

joel, this is to be fixed by your native dialogs i assume

Revision history for this message
Joelholdsworth (joelholdsworth) wrote :

Originator: NO

Yeah, that's right, and although I'm very busy right now, they should be
finished soon - hopefully before hell freezes over. Just got to finish off
this preview panel stuff.

nightrow (jb-benoit)
Changed in inkscape:
status: New → In Progress
Revision history for this message
Grant (gtaylor-buxton) wrote :

Can anyone tell me if this issue will be resolved. I've noticed that later versions of GIMP (also a GTK app) now comply with Windows system policy which older versions did not. You now cannot browse to the system drive through the open file dialogue box in GIMP.

Thanks.

Revision history for this message
ScislaC (scislac) wrote :

Can anyone confirm if this is still an issue on Windows?

Changed in inkscape:
status: In Progress → Incomplete
Revision history for this message
Kris (kris-degussem) wrote :

I do not see any folders appearing in the open file dialog in Inkscape (r10456).
Issue seems to be solved.

Changed in inkscape:
status: Incomplete → Fix Released
Revision history for this message
Kris (kris-degussem) wrote :

Typo: read hidden folders as opposed to folders in previous comment ;-)

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.