Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • Support for users without Kerberos principals.  Touchstone and CAMS are prerequisites for this.
  • -admin svnadmin groups; these are subsets of -committers groups and control who has access to manage a repository through the web application. If an a -admin svnadmin groups does not exist, all members of the -committers group will have access.

...

  1. Do not allow custom hook scripts for repositories accessible by the daemons--no "snap" accounts with write access to the hooks directories of such repositories.
  2. Develop machinery to make custom hook scripts execute as the committing user, or as the snap account.
  3. Accept a weak security model where users can gain access to other user's repositories with enough effort.

...