1
0
Fork 0
mirror of https://we.phorge.it/source/phorge.git synced 2024-11-16 03:42:41 +01:00
phorge-phorge/src/applications/owners
epriestley e5b402d13f Lock all reply-handler options in the upstream, plus cookie prefix
Summary:
Ref T7185. These settings shouldn't be unlocked anywhere. Specifically:

  - `reply-handler`: These are on the way out.
  - `reply-handler-domain`: Also hopefully on the way out; locked because a compromised administrator account can redirect replies.
  - `phabricator.cookie-prefix`: Not dangerous per se, but an admin could have a hard time fixing this if they changed it by accident since their session would become invalid immediately.

Test Plan: Browsed Config.

Reviewers: btrahan

Reviewed By: btrahan

Subscribers: epriestley

Maniphest Tasks: T7185

Differential Revision: https://secure.phabricator.com/D11764
2015-02-13 11:00:09 -08:00
..
application Remove getIconName from all applications 2015-01-30 12:11:21 -08:00
conduit Minor formatting changes 2014-10-08 08:39:49 +11:00
config Lock all reply-handler options in the upstream, plus cookie prefix 2015-02-13 11:00:09 -08:00
controller Policy - move some owners code into an editor class and check policy better 2015-02-03 11:41:15 -08:00
editor Policy - move some owners code into an editor class and check policy better 2015-02-03 11:41:15 -08:00
mail Applied various linter fixes. 2014-06-09 16:04:12 -07:00
phid Rename PHIDType classes 2014-07-24 08:05:46 +10:00
query Rename PhabricatorApplication subclasses 2014-07-23 10:03:09 +10:00
storage Policy - move some owners code into an editor class and check policy better 2015-02-03 11:41:15 -08:00
typeahead Rename PhabricatorApplication subclasses 2014-07-23 10:03:09 +10:00