After the upgrade from alpha2 to HEAD, the drushrc.php is world-readable:

-rwxr-xr-x  1 aegir aegir    303065 jan 14 17:06 drushrc.php

This defeats the whole idea of isolating the credentials in that file.

Comments

anarcat’s picture

Assigned: Unassigned » anarcat

I have a fix underway.

anarcat’s picture

Status: Active » Fixed

Fixed in d6b58e5

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.

  • Commit 03eb58c on debian, dev-dns, dev-envobject, dev-koumbit, dev-log_directory, dev-migrate_aliases, dev-multiserver-install, dev-newhooks, dev-nginx, dev-platform_management, dev-ports, dev-purgebackup, dev-restore, dev-services, dev-simplerinstaller, dev-site_rename, dev-ssl, dev_716166_apache_conf, dev_dns, dev_server_verify, prod-koumbit, dev-ssl-ip-allocation-refactor, dev-1205458-move_sites_out_of_platforms, 7.x-3.x, dev-subdir-multiserver, 6.x-2.x-backports, dev-helmo-3.x authored by anarcat:
    #685882 - set permissions properly on the drushrc after verification