Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create /etc/thelounge directory with 0700 permissions #72

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

awfulcooking
Copy link

Sensitive information is protected by thelounge/thelounge#205 for Docker builds, but deb installs didn't benefit, due to the home dir already existing - created at build time.

Sensitive information is protected by thelounge/thelounge#205 for
Docker builds, but deb installs didn't benefit, due to the home dir
already existing - created at build time.
awfulcooking added a commit to awfulcooking/thelounge that referenced this pull request Sep 5, 2021
Helps to prevent and retrospectively address issues like
thelounge/thelounge-deb#72

Obviously some sysadmins may want the directory to be world-readable,
but presently, that isn't safe.

This commit could be omitted or later reverted if sensitive data
protection is ensured through other means - e.g. with patches for
existing files, and an emphasis at review time to catch over-exposure in
the future ✌
@brunnre8
Copy link
Member

brunnre8 commented Sep 5, 2021

700 is overkill, certainly for the top level config folder

@brunnre8
Copy link
Member

brunnre8 commented Sep 5, 2021

if you want to guard against logs / vapid to be readable, fix those instead please

@awfulcooking
Copy link
Author

awfulcooking commented Sep 5, 2021 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants