[Geoserver-devel] [JIRA] (GEOS-7744) Please make defaults read-only

Anonymous created an issue

GeoServer / ImprovementGEOS-7744

Please make defaults read-only

Issue Type:

ImprovementImprovement

Assignee:

Unassigned

Components:

WFS

Created:

14/Sep/16 3:10 PM

Labels:

security wfs defaults

Priority:

MediumMedium

Reporter:

Anonymous

By default GeoServer will allow full WFS transactions, letting anyone who can access the server edit and delete data. This leads to many GeoServers running with that configuration without their administrators knowing. One can trivially find many such servers, ran by companies, universities, government agencies, free projects, etc.

Of course this could be considered oversight on the user’s part but I would highly suggest safe, restrictive defaults. Users (including me) are “stupid” and will use whatever works, ignoring possible problems in features they do not use.

Please do not allow WFS transactions by default.

I assume that this will apply to other services as well, but only looked at WFS. Please spread it to other parts of GeoServer as needed.

Add Comment

Add Comment

This message was sent by Atlassian JIRA (v1000.319.1#100012-sha1:913341f)

Atlassian logo