Hi Marcus,

Thanks for reporting this!

Marcus C. Gottwald wrote:
> Please note that this change does not match the syntax suggested for
> the value of DefaultUrlHost in LocalSite.cfg: A trailing slash is
> given in the default config but excluded from the first pair of
> brackets in the above regular expression.
> 
>   quantum3:~# grep DefaultUrlHost /etc/twiki/LocalSite.cfg_DISTR
>   $TWiki::cfg{DefaultUrlHost} = 'http://localhost/';
> 
> Lazy people who have simple never set DefaultUrlHost (because up to
> now there was no need to) might go slightly crazy until they have
> finally found out which value they need to change AND that the
> trailing slash must be omitted...

Can you provide a patch? I am just sponsoring twiki and I am not
familiar enough with it yet. Sven is on holidays, so he might be away
from the computer at the moment.

But I can upload a fix, reopen this bug, or we can just open a new one,
as this is no longer a security issue as I understand it, just a bug
introduced by this security fix.

Thanks for your input, and happy hacking!


-- 
  ยท''`.             If I can't dance to it, it's not my revolution
 : :' :                                            -- Emma Goldman
 `. `'           Proudly running Debian GNU/Linux (unstable)
   `-     www.amayita.com  www.malapecora.com  www.chicasduras.com

Reply via email to