On Tue, Jan 12, 2010 at 10:40 AM, Ivan Zahariev <rrdt...@famzah.net> wrote:
> Hi devs,
>
> I've first discussed this at the "users" list and there was no big
> interest but also no negative feedback there. Therefore I'm suggesting
> this to you now:
>
> Would you make the ".svn" directories not accessible by "others" (thus
> being accessible only by the "owner" and "group") ?
>
> You can review the full thread along with the security problem
> description and a patch at the following address:
> http://mail-archives.apache.org/mod_mbox/subversion-users/201001.mbox/%3c4b4b05e8.1060...@famzah.net%3e

There do exist people (unfortunately) who want to share wcs between
users.  In the future where there's only one .svn per wc, I think this
solution is great: make them private when created, but if somebody
chmods them public, it sticks. But while we still have tons of .svns
(we do still even on trunk, right?) that seems like it would make this
sort of use impossible.

--dave


-- 
glas...@davidglasser.net | langtonlabs.org | flickr.com/photos/glasser/

Reply via email to