https://redmine.lighttpd.net/https://redmine.lighttpd.net/favicon.ico?13667327412006-05-16T01:23:06Zlighty labsLighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=15722006-05-16T01:23:06Zmelo
<ul></ul><p>I'm using this patch with 1.4.9 still in the test environment.</p>
<p>I want to update it to 1.4.11 before putting this in production.</p>
<p><em>'_'Note well:</em>'_' after uploading the file, I noticed a cosmetic typo. The configuration option should be <code>path-elements</code> and not <code>path_elements</code>.</p>
<p>This will change in a future version of this patch.</p>
<p>Security-wyse, I believe that this patch does not remove more security and control than what it is expected to remove. Please post any problems you find with it.</p>
<p>Thanks,</p> Lighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=15732006-05-16T01:26:54Zmelo
<ul></ul><p>Hi,</p>
<p>fixed cosmetic bug: <code>secdownload.path_elements</code> was renamed to <code>secdownload.path-elements</code> to be more consistent with other options.</p>
<p>Still using this on a test environment.</p> Lighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=107002016-12-22T05:56:15Zgstrauss
<ul><li><strong>Related to</strong> <i><a class="issue tracker-2 status-5 priority-3 priority-lowest closed" href="/issues/1904">Feature #1904</a>: mod_secdownload option to include url GET parameters in md5</i> added</li></ul> Lighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=107022016-12-22T05:57:22Zgstrauss
<ul><li><strong>Description</strong> updated (<a title="View differences" href="/journals/10702/diff?detail_id=9204">diff</a>)</li><li><strong>Status</strong> changed from <i>New</i> to <i>Need Feedback</i></li><li><strong>Assignee</strong> deleted (<del><i>jan</i></del>)</li></ul><p>Is this feature still desirable?</p>
<p>As noted in <a class="issue tracker-2 status-5 priority-3 priority-lowest closed" title="Feature: mod_secdownload option to include url GET parameters in md5 (Fixed)" href="https://redmine.lighttpd.net/issues/1904">#1904</a>, arbitrary validation could be accomplished using a FastCGI authorizer in lieu of mod_secdownload, allowing the creation of the keys to be collocated with the code which validates the keys, instead of trying to extend mod_secdownload in a variety of ways.</p> Lighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=107142016-12-23T09:45:22Zgstrauss
<ul><li><strong>Status</strong> changed from <i>Need Feedback</i> to <i>Patch Pending</i></li><li><strong>Target version</strong> set to <i>1.4.45</i></li></ul> Lighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=107162016-12-23T16:38:54Zmelo
<ul></ul><p>Hello,</p>
<p>although we still use this patch in production, we are actually phasing it out at this moment to use a mechanism like what you describe, an authoriser.</p>
<p>I don't plan on using it anymore, so from my point of view, this ticket can be closed.</p>
<p>Thanks,</p> Lighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=107452017-01-09T23:02:18Zgstrauss
<ul><li><strong>Target version</strong> changed from <i>1.4.45</i> to <i>1.4.46</i></li></ul> Lighttpd - Feature #646: secdownload.path_elements supporthttps://redmine.lighttpd.net/issues/646?journal_id=108902017-02-25T20:55:08Zgstrauss
<ul><li><strong>Status</strong> changed from <i>Patch Pending</i> to <i>Fixed</i></li><li><strong>% Done</strong> changed from <i>0</i> to <i>100</i></li></ul><p>Applied in changeset <a class="changeset" title="[mod_secdownload] new directives modify hash path (fixes #646, fixes #1904) secdownload.path-seg..." href="https://redmine.lighttpd.net/projects/lighttpd/repository/14/revisions/afce434e0b0ee517fef06cf32d3f9de25ceddc14">afce434e0b0ee517fef06cf32d3f9de25ceddc14</a>.</p>