Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Packages wiki page can be edited by *anyone* #268

Open
kierenj opened this issue Mar 8, 2022 · 7 comments
Open

Packages wiki page can be edited by *anyone* #268

kierenj opened this issue Mar 8, 2022 · 7 comments

Comments

@kierenj
Copy link

kierenj commented Mar 8, 2022

Seems a major security issue!

@jwerle
Copy link
Member

jwerle commented Mar 8, 2022

@kierenj I did indeed see your tests! We have not had the ability to control this and this hasn't really been an issue for us, yet. However, GitHub now allows us to restrict edit access

image

I am not sure what the best path here is. We could create a team for authors like: authors. Folks can request access to this team by opening an issue.

cc @stephenmathieson @Isty001 @clibs/core - what do you think?

@stephenmathieson
Copy link
Member

IMO we shouldn't fix what isn't broken. We've been using a public wiki for nearly 10 years and haven't had a single problem with it.

@jwerle
Copy link
Member

jwerle commented Mar 8, 2022

IMO we shouldn't fix what isn't broken. We've been using a public wiki for nearly 10 years and haven't had a single problem with it.

this is true! if it ain't broke, don't fix it!

@kierenj
Copy link
Author

kierenj commented Mar 8, 2022

No probs, of course I would say there wouldn’t ever be an issue right up until the point in time an issue occurs, but I am not well placed to have much of an opinion on it!

@stephenmathieson
Copy link
Member

stephenmathieson commented Mar 8, 2022

Fortunately if there is a problem, we can easily revert the change(s) and set up an "authors" group. The wiki is just another Git repository 😄

revert button

@hyperupcall
Copy link
Contributor

hyperupcall commented Aug 26, 2023

Another data point, the Bats wiki was defaced on July 15th, 2023. Somewhat odd, especailly considering Bats is a relatively niche tool. They kept the Wiki publically editable afterwards, but plan to make it contributors-only if it becomes a reoccuring problem.

@bcomnes
Copy link
Member

bcomnes commented Aug 29, 2023

+1 on keeping it open until its an issue. I will subscribe to https://github.com/clibs/clib/wiki.atom to help monitor. Any other feed junkies please help out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants