View Issue Details

IDProjectCategoryView StatusLast Update
0011400mantisbtsecuritypublic2010-02-22 14:34
Reporterdhx Assigned Todhx  
PrioritynormalSeverityminorReproducibilityN/A
Status closedResolutionfixed 
Product Version1.2.0 
Target Version1.2.0Fixed in Version1.2.0 
Summary0011400: Increase default $g_view_configuration_threshold to ADMINISTRATOR
Description

By default, $g_view_configuration_threshold is currently set to DEVELOPER. This option should really be changed to have a default of ADMINISTRATOR, as the configuration of MantisBT can contain sensitive information.

There won't be impact to current installations, as users at DEVELOPER level have no links whatsoever in the UI to the adm and manage pages of MantisBT.

TagsNo tags attached.

Activities

There are no notes attached to this issue.

Related Changesets

MantisBT: master-1.2.x 589ef8ff

2010-01-15 08:55

dhx


Details Diff
Fix 0011400: Increase default $g_view_configuration_threshold

By default, $g_view_configuration_threshold is currently set to
DEVELOPER. This option should really be changed to have a default of
ADMINISTRATOR, as the configuration of MantisBT can contain sensitive
information.

There won't be impact to current installations, as users at DEVELOPER
level have no links whatsoever in the UI to the adm_ and manage_ pages
of MantisBT.
Affected Issues
0011400
mod - config_defaults_inc.php Diff File

MantisBT: master 5c727ba9

2010-01-15 08:55

dhx


Details Diff
Fix 0011400: Increase default $g_view_configuration_threshold

By default, $g_view_configuration_threshold is currently set to
DEVELOPER. This option should really be changed to have a default of
ADMINISTRATOR, as the configuration of MantisBT can contain sensitive
information.

There won't be impact to current installations, as users at DEVELOPER
level have no links whatsoever in the UI to the adm_ and manage_ pages
of MantisBT.
Affected Issues
0011400
mod - config_defaults_inc.php Diff File

MantisBT: master-1.2.x 9b1fbd77

2010-01-16 21:17

dhx


Details Diff
Fix 0011400: Update documentation of $g_view_configuration_threshold

Commit 5c727ba9ac508201434e7d5361297f367a206463 changed the default
value of $g_view_configuration_threshold from VIEWER to ADMINISTRATOR.
However, I forgot to update the documentation to reflect this change.

Thank you Victor for reminding me!

Note that this backport includes documentation of the configuration
view/set threshold options that were introduced in commit
fce04e6597310e9dd644612348354dc055e99dfa but weren't backported to the
1.2.x branch at that point of time.
Affected Issues
0011400
mod - docbook/adminguide/en/configuration.sgml Diff File

MantisBT: master e1d134e7

2010-01-16 21:17

dhx


Details Diff
Fix 0011400: Update documentation of $g_view_configuration_threshold

Commit 5c727ba9ac508201434e7d5361297f367a206463 changed the default
value of $g_view_configuration_threshold from VIEWER to ADMINISTRATOR.
However, I forgot to update the documentation to reflect this change.

Thank you Victor for reminding me!
Affected Issues
0011400
mod - docbook/adminguide/en/configuration.sgml Diff File