Textpattern CMS support forum
You are not logged in. Register | Login | Help
- Topics: Active | Unanswered
[contrib] Live TXP Examples Site
So I’m thinking pretty seriously about pushing forward with a TXP live examples site as described here , But I need some advice on logistics.
- How much and what kind of damage can a user with “publisher” rights do to a server from a TXP install?
- Should I set up an administered or a self register for new accounts?
Let’s discuss the specifics of how this site would work. Have at it?
Offline
Re: [contrib] Live TXP Examples Site
- A publisher could delete everyone’s accounts, so maybe a manging or copy editor.
- I think monitored is the way to go. Self-registered could result in a lot of abuse.
Last edited by jm (2007-04-09 04:18:42)
Offline
#3 2007-04-09 06:23:29
- zem
- Developer Emeritus
- From: Melbourne, Australia
- Registered: 2004-04-08
- Posts: 2,579
Re: [contrib] Live TXP Examples Site
A publisher can run arbitrary PHP code and MySQL queries. They’ll have read access to at least some of the filesystem, and in some circumstances they might be able to modify or delete files.
Alex
Offline
Re: [contrib] Live TXP Examples Site
Sounds like it would be best to do…
- an administered account system
- with managing editor accounts. plugins installed on request (or is that too draconian?)
Offline
Re: [contrib] Live TXP Examples Site
I think that would not be draconian. As other stated above, I think that’s the best way to prevent abuse.
…Prrrrrrrr…
Offline
Re: [contrib] Live TXP Examples Site
was this idea advanced any further? i’m interested in how others put together their txp sites!
Offline