[xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
Hi guys, I installed the "Admin Tools" plugin http://extensions.xwiki.org/xwiki/bin/view/Extension/AdminTools And found that half the stuff didn't work anyway. Regardless, carrying on, I am hoping the User Rights tool will be helpful, however it can't seem to check the most important user: the U

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 15:15, Paul Harris wrote: > Hi guys, > > I installed the "Admin Tools" plugin > http://extensions.xwiki.org/xwiki/bin/view/Extension/AdminTools > > > snip > > And what is worse, I discovered by accident that the Unregistered User can > access the space! > For example, an unregist

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Asiri Rathnayake
Hi, On Thu, Jun 30, 2011 at 8:15 AM, Paul Harris wrote: > Hi guys, > > I installed the "Admin Tools" plugin > http://extensions.xwiki.org/xwiki/bin/view/Extension/AdminTools > > And found that half the stuff didn't work anyway. > > Regardless, carrying on, I am hoping the User Rights tool will b

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Thomas Mortagne
On Thu, Jun 30, 2011 at 09:39, Asiri Rathnayake wrote: > Hi, > > On Thu, Jun 30, 2011 at 8:15 AM, Paul Harris wrote: > >> Hi guys, >> >> I installed the "Admin Tools" plugin >> http://extensions.xwiki.org/xwiki/bin/view/Extension/AdminTools >> >> And found that half the stuff didn't work anyway.

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Thomas Mortagne
On Thu, Jun 30, 2011 at 09:22, Paul Harris wrote: > On 30 June 2011 15:15, Paul Harris wrote: > >> Hi guys, >> >> I installed the "Admin Tools" plugin >> http://extensions.xwiki.org/xwiki/bin/view/Extension/AdminTools >> >> >> snip > >> >> And what is worse, I discovered by accident that the Unre

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 15:49, Thomas Mortagne wrote: > On Thu, Jun 30, 2011 at 09:39, Asiri Rathnayake > wrote: > > Hi, > > > > On Thu, Jun 30, 2011 at 8:15 AM, Paul Harris > wrote: > > > >> Hi guys, > >> > >> I installed the "Admin Tools" plugin > >> http://extensions.xwiki.org/xwiki/bin/view/Extensi

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 15:50, Thomas Mortagne wrote: > On Thu, Jun 30, 2011 at 09:22, Paul Harris wrote: > > On 30 June 2011 15:15, Paul Harris wrote: > > > >> Hi guys, > >> > >> I installed the "Admin Tools" plugin > >> http://extensions.xwiki.org/xwiki/bin/view/Extension/AdminTools > >> > >> > >> sn

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Thomas Mortagne
On Thu, Jun 30, 2011 at 09:57, Paul Harris wrote: > On 30 June 2011 15:49, Thomas Mortagne wrote: > >> On Thu, Jun 30, 2011 at 09:39, Asiri Rathnayake >> wrote: >> > Hi, >> > >> > On Thu, Jun 30, 2011 at 8:15 AM, Paul Harris >> wrote: >> > >> >> Hi guys, >> >> >> >> I installed the "Admin Tools

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Andreas Hahn
Paul, actually XWiki offers quite some fine grained rights administration. Go to the XWiki administration page and then to 'rights' administration. There you should see a couple of 'Prevent unregistered users from ...' options. Prevent unregistered users from viewing pages, regardless of the pa

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 16:26, Andreas Hahn wrote: > Paul, > > actually XWiki offers quite some fine grained rights administration. > > Go to the XWiki administration page and then to 'rights' administration. > There you should see a couple of 'Prevent unregistered users from ...' > options. > > Prevent

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 16:20, Thomas Mortagne wrote: > On Thu, Jun 30, 2011 at 09:57, Paul Harris wrote: > > On 30 June 2011 15:49, Thomas Mortagne > wrote: > > > >> On Thu, Jun 30, 2011 at 09:39, Asiri Rathnayake > >> wrote: > >> > Hi, > >> > > >> > On Thu, Jun 30, 2011 at 8:15 AM, Paul Harris > >>

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Andreas Hahn
Am 30.06.2011 10:33, schrieb Paul Harris: > > I'm a bit confused by this... I don't see how you could call this particular > option "fine grained" > > I still want unregistered users to be able to see the front page, and maybe > a page or two more - describing who we are and how to join up. > > If

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Thomas Mortagne
On Thu, Jun 30, 2011 at 10:39, Paul Harris wrote: > On 30 June 2011 16:20, Thomas Mortagne wrote: > >> On Thu, Jun 30, 2011 at 09:57, Paul Harris wrote: >> > On 30 June 2011 15:49, Thomas Mortagne >> wrote: >> > >> >> On Thu, Jun 30, 2011 at 09:39, Asiri Rathnayake >> >> wrote: >> >> > Hi, >>

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 16:58, Thomas Mortagne wrote: > On Thu, Jun 30, 2011 at 10:39, Paul Harris wrote: > > On 30 June 2011 16:20, Thomas Mortagne > wrote: > > > >> On Thu, Jun 30, 2011 at 09:57, Paul Harris wrote: > >> > On 30 June 2011 15:49, Thomas Mortagne > >> wrote: > >> > > >> >> On Thu, Jun

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
> > >> > >> > >> > When the unregistered user looks at the main welcome page, they can see >> the >> > content, but the black-to-grey styling is broken (I'm using the >> NightFall >> > colours with Colibri skin). >> >> If you want unregistered user to see main page then it should have the >> right

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 16:53, Andreas Hahn wrote: > Am 30.06.2011 10:33, schrieb Paul Harris: > > > > I'm a bit confused by this... I don't see how you could call this > particular > > option "fine grained" > > > > I still want unregistered users to be able to see the front page, and > maybe > > a page

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Thomas Mortagne
On Thu, Jun 30, 2011 at 11:11, Paul Harris wrote: >> >> >>> > >>> > >>> > When the unregistered user looks at the main welcome page, they can see >>> the >>> > content, but the black-to-grey styling is broken (I'm using the >>> NightFall >>> > colours with Colibri skin). >>> >>> If you want unregi

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Thomas Mortagne
On Thu, Jun 30, 2011 at 11:18, Paul Harris wrote: > On 30 June 2011 16:53, Andreas Hahn wrote: > >> Am 30.06.2011 10:33, schrieb Paul Harris: >> > >> > I'm a bit confused by this... I don't see how you could call this >> particular >> > option "fine grained" >> > >> > I still want unregistered us

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Andreas Hahn
> Hi Andreas, > > Your site is perfect for illustrating my concerns about the "open by > default" configuration of xwiki. > > I was able to register an account (I used my real email, but it could've > been a fake one), and was able to make a comment on your page here: > http://shept.org/docs/Shept

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 17:28, Thomas Mortagne wrote: > On Thu, Jun 30, 2011 at 11:11, Paul Harris wrote: > >> > >> > >>> > > >>> > > >>> > When the unregistered user looks at the main welcome page, they can > see > >>> the > >>> > content, but the black-to-grey styling is broken (I'm using the > >>> Ni

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 30 June 2011 18:09, Andreas Hahn wrote: > > > Hi Andreas, > > > > Your site is perfect for illustrating my concerns about the "open by > > default" configuration of xwiki. > > > > I was able to register an account (I used my real email, but it could've > > been a fake one), and was able to mak

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Thomas Mortagne
On Fri, Jul 1, 2011 at 01:15, Paul Harris wrote: > On 30 June 2011 17:28, Thomas Mortagne wrote: > >> On Thu, Jun 30, 2011 at 11:11, Paul Harris wrote: >> >> >> >> >> >>> > >> >>> > >> >>> > When the unregistered user looks at the main welcome page, they can >> see >> >>> the >> >>> > content, b

Re: [xwiki-users] Crazy-bad security

2011-06-30 Thread Paul Harris
On 1 July 2011 14:52, Thomas Mortagne wrote: > On Fri, Jul 1, 2011 at 01:15, Paul Harris wrote: >> On 30 June 2011 17:28, Thomas Mortagne wrote: >> >>> On Thu, Jun 30, 2011 at 11:11, Paul Harris wrote: >>> >> >>> >> >>> >>> > >>> >>> > >>> >>> > When the unregistered user looks at the main welc

Re: [xwiki-users] Crazy-bad security

2011-07-01 Thread Thomas Mortagne
On Fri, Jul 1, 2011 at 08:56, Paul Harris wrote: > On 1 July 2011 14:52, Thomas Mortagne wrote: >> On Fri, Jul 1, 2011 at 01:15, Paul Harris wrote: >>> On 30 June 2011 17:28, Thomas Mortagne wrote: >>> On Thu, Jun 30, 2011 at 11:11, Paul Harris wrote: >> >> >>> > >>> >