mirror of
https://github.com/ArchiveBox/ArchiveBox.git
synced 2026-04-25 17:16:00 +03:00
[GH-ISSUE #1038] Limit wiki edit permissions #649
Labels
No labels
expected: maybe someday
expected: next release
expected: release after next
expected: unlikely unless contributed
good first ticket
help wanted
pull-request
scope: all users
scope: windows users
size: easy
size: hard
size: medium
size: medium
status: backlog
status: blocked
status: done
status: idea-phase
status: needs followup
status: wip
status: wontfix
touches: API/CLI/Spec
touches: configuration
touches: data/schema/architecture
touches: dependencies/packaging
touches: docs
touches: js
touches: views/replayers/html/css
why: correctness
why: functionality
why: performance
why: security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/ArchiveBox#649
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @antiops on GitHub (Oct 20, 2022).
Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/1038
Noticed some sus links in the wiki while going through the history, an IP logger and some zip files that probably got removed by GitHub. I reverted the edits that I found to whatever they used to be, they only started to pop up a couple months ago on those 2 pages.
Restricting editing to collaborators should probably be enabled so the pages cant be edited/created/deleted by anyone.
@pirate commented on GitHub (Oct 27, 2022):
Thank you so much for alerting me of this! I just changed the edit permissions.
Sad to see they were being abuse for malware links, it makes sense but didn't think to check for this myself.
I'd like to send you a $50 bounty for discovering this. Whats your preferred method? I can send with Venmo/Zelle/ETH/BTC/XMR/USDC
@antiops commented on GitHub (Oct 31, 2022):
I'd love it if you could donate it to Archive.org, it'd be put to much better use than in my pocket :bowtie: