| home | help | back | first | fref | pref | prev | next | nref | lref | last | post |
It is possible to make the script smart enough to not allow symlinks that are either (a) absolute or (b) contain a ".." component, and to do the same for any symlinks that are pointed to by the initial symlink. In other words, it *is* possible to allow symlinks to files within a users account without compromising security on charon.
| home | help | back | first | fref | pref | prev | next | nref | lref | last | post |