Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Incomplete
-
1.0.1, 1.1.0, 0.98.12, 1.2.0, 2.0.0
-
None
-
None
-
None
Description
DLS, DLR, and replication queue items should not include arbitrary full pathnames. Audit and fix where we have this. Even with znodes properly secured it seems better to simply record a filename in the queue item and build the full path to the file in storage under a preconfigured root directory with secure permissions.