[xwiki-users] Can admins see MyDashboards?
I'm concerned some may be using the MyDashboard feature of their profile page to post inappropriate content. What access rights do admins have on pages that are located off the MyDashboard or where permissions are set so that only some registered users may see them? Let's say a user was using our site to post/distribute/develop child pornography or malware? Patrick -- || | | |||| || || | |||| ||| | ||| Patrick Masson General Manager, Director & Secretary to the Board Open Source Initiative 855 El Camino Real, Ste 13A, #270 Palo Alto, CA 94301 United States Skype: massonpj sip: [email protected] <https://www.getonsip.com/[email protected]> Ph: (970) 4MASSON Em: [email protected] <mailto:[email protected]> Ws: www.opensource.org <http://www.opensource.org>
Asking again with more detail... I'm concerned some may be using the MyDashboard feature of their profile page to post inappropriate content. For example, a spam user could register for an account, and then make pages private to a group and the organization and admin may not know. Let's say a user was using our site to post/distribute/develop child pornography or malware? What access rights do admins have on pages that are located off the MyDashboard or where permissions are set so that only some registered users may see them? I tested this my creating a private page on my profile's MyDashboard, then logged in as Admin. When, as Admin, I searched the Document Index in a space by my user id, I did see the private pages. However, with 100's of users this might not be practical. I guess I am really trying to understand best practices that others may use in managing the wiki to avoid nefarious use. Thanks Patrick -- || | | |||| || || | |||| ||| | ||| Patrick Masson General Manager, Director & Secretary to the Board Open Source Initiative 855 El Camino Real, Ste 13A, #270 Palo Alto, CA 94301 United States Skype: massonpj sip: [email protected] <https://www.getonsip.com/[email protected]> Ph: (970) 4MASSON Em: [email protected] <mailto:[email protected]> Ws: www.opensource.org <http://www.opensource.org>
Admin right is not deniable and it implies at the other rights except programming. See http://extensions.xwiki.org/xwiki/bin/view/Extension/Security+Module#HDefaul... . So admins should be able to view/edit/delete any page from the wiki they administer, independent of the rights set on those pages. A bad user could write though something like this: {{velocity}} #if ($hasAdmin) Nice content #else Bad content #end {{/velocity}} To prevent this you can use the watch list to get a mail with the changes produced in the wiki and review those changes regularly (i.e. look at the raw content not just at the rendered content) . Hope this helps, Marius. On Fri, Mar 28, 2014 at 6:52 PM, Patrick Masson <[email protected]> wrote:
I'm concerned some may be using the MyDashboard feature of their profile page to post inappropriate content. What access rights do admins have on pages that are located off the MyDashboard or where permissions are set so that only some registered users may see them?
Let's say a user was using our site to post/distribute/develop child pornography or malware?
Patrick
-- || | | |||| || || | |||| ||| | ||| Patrick Masson General Manager, Director & Secretary to the Board Open Source Initiative 855 El Camino Real, Ste 13A, #270 Palo Alto, CA 94301 United States Skype: massonpj sip: [email protected] <https://www.getonsip.com/[email protected]> Ph: (970) 4MASSON Em: [email protected] <mailto:[email protected]> Ws: www.opensource.org <http://www.opensource.org> _______________________________________________ users mailing list [email protected] http://lists.xwiki.org/mailman/listinfo/users
I replied on the first thread. On Tue, Apr 1, 2014 at 5:59 PM, Patrick Masson <[email protected]> wrote:
Asking again with more detail...
I'm concerned some may be using the MyDashboard feature of their profile page to post inappropriate content. For example, a spam user could register for an account, and then make pages private to a group and the organization and admin may not know. Let's say a user was using our site to post/distribute/develop child pornography or malware?
What access rights do admins have on pages that are located off the MyDashboard or where permissions are set so that only some registered users may see them? I tested this my creating a private page on my profile's MyDashboard, then logged in as Admin. When, as Admin, I searched the Document Index in a space by my user id, I did see the private pages. However, with 100's of users this might not be practical.
I guess I am really trying to understand best practices that others may use in managing the wiki to avoid nefarious use.
Thanks Patrick
-- || | | |||| || || | |||| ||| | ||| Patrick Masson General Manager, Director & Secretary to the Board Open Source Initiative 855 El Camino Real, Ste 13A, #270 Palo Alto, CA 94301 United States Skype: massonpj sip: [email protected] <https://www.getonsip.com/[email protected]> Ph: (970) 4MASSON Em: [email protected] <mailto:[email protected]> Ws: www.opensource.org <http://www.opensource.org>
_______________________________________________ users mailing list [email protected] http://lists.xwiki.org/mailman/listinfo/users
participants (2)
-
Marius Dumitru Florea -
Patrick Masson