Changeset 111 for trunk/DNSDB.pm


Ignore:
Timestamp:
08/01/11 19:24:30 (13 years ago)
Author:
Kris Deugau
Message:

/trunk

Add ACL checks to prevent contructed-URL ACL bypasses on SOA records, group
add/edit/delete, axfr import; correct logic in bulk domain ACL check

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/DNSDB.pm

    r108 r111  
    759759                |c:\d+  # clone
    760760                        # custom.  no, the leading , is not a typo
    761                 |C:(?:,(?:group|user|domain|record|self)_(?:edit|create|delete))+
     761                |C:(?:,(?:group|user|domain|record|self)_(?:edit|create|delete))*
    762762                )$/x;
    763763# bleh.  I'd call another function to do my dirty work, but we're in the middle of a transaction already.
Note: See TracChangeset for help on using the changeset viewer.