do not allow gid write access by default, the gid user can still write for now, see #1629
This commit is contained in:
parent
afd2746bcc
commit
a9ebd14882
|
@ -126,15 +126,15 @@ doone() {
|
||||||
# Set the file readable only for the AlternC User
|
# Set the file readable only for the AlternC User
|
||||||
mkdir -p "$REP"
|
mkdir -p "$REP"
|
||||||
chown -R $GID:$GID "$REP"
|
chown -R $GID:$GID "$REP"
|
||||||
chmod 2770 -R "$REP"
|
chmod 2750 -R "$REP"
|
||||||
|
|
||||||
# # Delete existings ACL
|
# # Delete existings ACL
|
||||||
# # Set the defaults acl on all the files
|
# # Set the defaults acl on all the files
|
||||||
# setfacl -b -k -n -R -m d:g:alterncpanel:rwx -m d:u::rwx -m d:g::rwx -m d:u:$GID:rwx -m d:g:$GID:rwx -m d:o::--- -m d:mask:rwx\
|
# setfacl -b -k -n -R -m d:g:alterncpanel:rwx -m d:u::rwx -m d:g::rwx -m d:u:$GID:rwx -m d:g:$GID:rwx -m d:o::--- -m d:mask:rwx\
|
||||||
# -Rm g:alterncpanel:rwx -m u:$GID:rwx -m g:$GID:rwx -m mask:rwx\
|
# -Rm g:alterncpanel:rwx -m u:$GID:rwx -m g:$GID:rwx -m mask:rwx\
|
||||||
# "$REP"
|
# "$REP"
|
||||||
setfacl -bknR -m d:u:alterncpanel:rwx -m d:g:alterncpanel:rwx -m u:alterncpanel:rwx -m g:alterncpanel:rwx -m d:o::--- -m o::---\
|
setfacl -bknR -m d:u:alterncpanel:rwx -m d:g:alterncpanel:r-x -m u:alterncpanel:rwx -m g:alterncpanel:r-x -m d:o::--- -m o::---\
|
||||||
-m d:u:$GID:rwx -m d:g:$GID:rwx -m u:$GID:rwx -m g:$GID:rwx -m d:mask:rwx -m mask:rwx "$REP"
|
-m d:u:$GID:rwx -m d:g:$GID:r-x -m u:$GID:rwx -m g:$GID:r-x -m d:mask:rwx -m mask:rwx "$REP"
|
||||||
|
|
||||||
fixtmp $GID
|
fixtmp $GID
|
||||||
read GID LOGIN || true
|
read GID LOGIN || true
|
||||||
|
|
Loading…
Reference in New Issue