WUI: the error message page for a writeable file/directory nonobviously includes the write cap #1649

Open
opened 2011-12-31 00:29:29 +00:00 by davidsarah · 0 comments
davidsarah commented 2011-12-31 00:29:29 +00:00
Owner

In the case of a directory, for example, the target URL of the 'More info on this directory' link includes the write cap. This is not excess authority because the 'More info' page itself includes the write cap and so needs to know it, however, it's not visually obvious that by sending someone just the HTML file of the error page, you are giving them the write cap.

(OTOH, I was prompted to file this ticket by someone who did exactly that and did understand that they were giving away the write cap.)

In the case of a directory, for example, the target URL of the 'More info on this directory' link includes the write cap. This is not excess authority because the 'More info' page itself includes the write cap and so needs to know it, however, it's not visually obvious that by sending someone just the HTML file of the error page, you are giving them the write cap. (OTOH, I was prompted to file this ticket by someone who did exactly that and **did** understand that they were giving away the write cap.)
tahoe-lafs added the
code-frontend-web
major
defect
1.9.0
labels 2011-12-31 00:29:29 +00:00
tahoe-lafs added this to the undecided milestone 2011-12-31 00:29:29 +00:00
Sign in to join this conversation.
No Milestone
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Reference: tahoe-lafs/trac-2024-07-25#1649
No description provided.