Re: Current security issues with KAuth support in KIO

2018-02-05 Thread Fabian Vogt
Hi, Am Sonntag, 4. Februar 2018, 23:47:26 CET schrieb Albert Astals Cid: > So we're having KF5 5.43 next week, has this been figured out? not quite, but it's on the right track (unlikely for 5.43 though). See below. Cheers, Fabian > I find this thread ended too open ended for my taste. > > Che

Re: Current security issues with KAuth support in KIO

2018-02-04 Thread Albert Astals Cid
So we're having KF5 5.43 next week, has this been figured out? I find this thread ended too open ended for my taste. Cheers, Albert El dissabte, 13 de gener de 2018, a les 23:55:16 CET, Luca Beltrame va escriure: > (please keep Fabian in CC, he's not subscribed and found out most of the > iss

Re: Current security issues with KAuth support in KIO

2018-01-14 Thread chinmoy ranjan
> Is someone already working on fixes for the above issues? Currently I am looking into the issues.

Re: Current security issues with KAuth support in KIO

2018-01-14 Thread Luca Beltrame
Il giorno Sun, 14 Jan 2018 11:12:15 +0100 Elvis Angelaccio ha scritto: > No, it's not. Despite the name, 'Persistence=session' just means the > privilege is kept for a few minutes. As discussed on IRC, this is an "issue" due to the fact that KIO can do much more than other KAuth-enabled program

Re: Current security issues with KAuth support in KIO

2018-01-14 Thread Elvis Angelaccio
On sabato 13 gennaio 2018 23:55:16 CET, Luca Beltrame wrote: (please keep Fabian in CC, he's not subscribed and found out most of the issues reported here) At openSUSE we have to request reviews by the security team before new polkit services get accepted. This is the case for the kio kauth he

Current security issues with KAuth support in KIO

2018-01-13 Thread Luca Beltrame
(please keep Fabian in CC, he's not subscribed and found out most of the issues reported here) At openSUSE we have to request reviews by the security team before new polkit services get accepted. This is the case for the kio kauth helper as well. While the security team raised concerns with the