Q: Change Permissions on Wiki People page?
I am Using Wiki Server 3 on a Mini Lion Server install.
I find it to be an intolerable security problem that, without logging in, any one can see my Wiki's "People Page"
At best it gives hackers a good starting point at guessing login names.
At worst, if someone uses a photo for their profile pic it gives predators a name & face.
I can disable the People Page entirely by editing the proper plist file, but then the whole page, and everyone's personal documents pages are completely inaccessable.
Is there a way to re-enable the People page, but make it available ONLY to logged in users? It doesn't treat "People" and personal pages like Wiki pages. I can't seem to find settings for permissions.
Thanks,
Joe
Mac mini, Mac OS X (10.7.1)
Posted on Sep 14, 2011 5:09 AM
I've encountered the same problem. We're running 10.7.2 and the only solution I've found is to edit the actual code to require that the user be authenticated in order to view the people page. This probably isn't a good long term solution, but just in case you're interested here's what I did.
1) Edit the file /usr/share/collabd/coreclient/app/controllers/people_controller.rb to include 'before_filter :ensure_user_is_authenticated' at the top of the PeopleController class definition.
2) Stop and restart the wiki server (serveradmin stop wiki;serveradmin start wiki).
This will prevent unauthenticated users from seeing the people pages. Note that this change will likely be overwritten when you upgrade.
Hope this helps.
Posted on Oct 18, 2011 8:57 AM


