From ae0475367c079624b6386cd421356b02995caebe Mon Sep 17 00:00:00 2001 From: www-data Date: Sun, 19 Mar 2006 22:01:43 +0000 Subject: [PATCH] web commit by joey --- doc/security.mdwn | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/doc/security.mdwn b/doc/security.mdwn index 09f3cedf9..5fda9e678 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -44,7 +44,7 @@ this wiki, BTW. ## svn commit logs -Anyone with svn commit access can forge "web commit from foo" and make it appeat on [[RecentChanges]] like foo committed. One way to avoid this would be to limit web commits to those done by a certian user. +Anyone with svn commit access can forge "web commit from foo" and make it appear on [[RecentChanges]] like foo committed. One way to avoid this would be to limit web commits to those done by a certian user. It's actually possible to force a whole series of svn commits to appear to have come just before yours, by forging svn log output. This could be guarded against somewhat by revision number scanning, since the forged revisions would duplicate the numbers of unforged ones. Or subversion could fix svn log to indent commit messages, which would make such forgery impossible.. -- 2.44.0