plainblack.com
Username Password
search
Bookmark and Share
View All Tickets
modproxy to circumvent security on uploads  (#3538)
Issue

What Martin describes in the wiki.

That is actually a grave security bug. So the default templates should be modified to not have the modproxy circumvent WebGUI's security. 

Koen de Jonge - ProcoliX
http://www.procolix.com
Hosting - WebGUI - Virtualization

Solution Summary
Comments
Graham
0
1/29/2008 10:43 am

This is set this way on purpose.  It is simple to change for people that need it, but imposes severe performance issues.

This isn't going to be changed.  Documentation could be changed if needed though.

knowmad
0
2/6/2008 11:06 pm
[quote]

This is set this way on purpose.  It is simple to change for people that need it, but imposes severe performance issues.

[/quote]

What do you mean by "severe performance issues"? The request is still being handled by Apache albeit the modperl instance instead of the light-weight modproxy. Please elaborate.

 

William 

----
Knowmad Technologies
http://www.knowmad.com

Graham
0
2/11/2008 11:18 am

I may have overstated the performance drawbacks, but there is still a lot more processing that has to be done to have modperl handle uploads.  JT explained the difference in the process on the dev mailing list.  If you have a large number of images used in your pages, you could start to see slowdowns on your site.

I've added a note about this to the WRE's modproxy template.  Any other recommendations for documentation changes are welcome.

knowmad
4
10/28/2008 5:03 pm
Actually this issue has been aptly addressed by some savvy rewrite rules in the modproxy template file that's part of WRE 0.8.5. However, the rules are broken (see http://www.webgui.org/bugs/tracker/9000). Hopefully the next release of the WRE will address this bug.
Details
Ticket Status Closed  
Rating4.0 
Submitted Bykoen 
Date Submitted2008-01-27 
Assigned To unassigned  
Date Assigned2012-02-12 
Assigned By 
Severity Fatal (can't continue until this is resolved)  
What's the bug in? WRE  
WebGUI / WRE Version 0.8.1  
URLbugs/tracker/modproxy-to-circumvent-security-on-uploads
Keywords
Ticket History
© 2012 Plain Black Corporation | All Rights Reserved