summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorHavoc Pennington <hp@redhat.com>2003-09-25 13:38:44 +0000
committerHavoc Pennington <hp@redhat.com>2003-09-25 13:38:44 +0000
commitc9cf30dc373b521cc243d8c75ac21b02a39c73e7 (patch)
tree0cb409287e535e9ee77ca191bb39ba98019def28
parent2b1d98c76bae38c2d6955f68b92919172c8ae53b (diff)
downloaddbus-c9cf30dc373b521cc243d8c75ac21b02a39c73e7.tar.gz
2003-09-25 Havoc Pennington <hp@pobox.com>
* bus/session.conf.in: fix security policy, reported by Seth Nickell
-rw-r--r--ChangeLog4
-rw-r--r--bus/session.conf.in6
-rw-r--r--doc/TODO2
3 files changed, 11 insertions, 1 deletions
diff --git a/ChangeLog b/ChangeLog
index 6317ef54..dc19e03d 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,7 @@
+2003-09-25 Havoc Pennington <hp@pobox.com>
+
+ * bus/session.conf.in: fix security policy, reported by Seth Nickell
+
2003-09-25 Seth Nickell <seth@gnome.org>
* python/examples/example-service.py:
diff --git a/bus/session.conf.in b/bus/session.conf.in
index 45945688..df76d33f 100644
--- a/bus/session.conf.in
+++ b/bus/session.conf.in
@@ -13,9 +13,13 @@
<servicedir>@EXPANDED_LIBDIR@/dbus-1.0/services</servicedir>
<policy context="default">
- <!-- Allow everything -->
+ <!-- Allow everything to be sent -->
+ <allow send_destination="*"/>
+ <!-- Allow everything to be received */
<allow eavesdrop="true"/>
+ <!-- Allow anyone to own anything -->
<allow own="*"/>
+ <!-- Allow any user to connect -->
<allow user="*"/>
</policy>
diff --git a/doc/TODO b/doc/TODO
index c70cc929..f1c8e6aa 100644
--- a/doc/TODO
+++ b/doc/TODO
@@ -92,4 +92,6 @@
- dbus_gproxy or dbus_g_proxy?
+ - add dbus_message_has_path(), maybe has_member/interface
+
- The OBJECT_PATH type is not documented in the spec.