moinwiki / moin-1.9

MoinMoin Wiki (1.9, also: 1.5a ... 1.8), stable, for production wikis
https://moinmo.in/
Other
140 stars 54 forks source link

default acl change? #6

Closed ThomasWaldmann closed 6 years ago

ThomasWaldmann commented 6 years ago

I recently installed a new wiki and was not very careful with the ACLs, so it used the default ACL (which is r/w for everybody).

Only a few days later the wiki had a thousand spam pages and about as many new "users" (spammers).

While the user creation is an annoyance by itself, the spam page creation could be avoid by just having u"All:read" as default ACL, forcing wiki admins to set up their own acl_rights_before and acl_rights_default.

The default acl could be changed at 2 places:

ReimarBauer commented 6 years ago

We could also exclude the action to create users by actions_excluded So that at least a config step has to be done.

ThomasWaldmann commented 6 years ago

see #16.

ThomasWaldmann commented 6 years ago

Guess I do a change at both places: