r/a=mkanat git-svn-id: svn://10.0.0.236/trunk@260809 18797224-902f-48f8-a5cc-f745e15eee43
76 lines
4.1 KiB
Cheetah
76 lines
4.1 KiB
Cheetah
[%# The contents of this file are subject to the Mozilla Public
|
|
# License Version 1.1 (the "License"); you may not use this file
|
|
# except in compliance with the License. You may obtain a copy of
|
|
# the License at http://www.mozilla.org/MPL/
|
|
#
|
|
# Software distributed under the License is distributed on an "AS
|
|
# IS" basis, WITHOUT WARRANTY OF ANY KIND, either express or
|
|
# implied. See the License for the specific language governing
|
|
# rights and limitations under the License.
|
|
#
|
|
# The Original Code is the Bugzilla Bug Tracking System.
|
|
#
|
|
# The Initial Developer of the Original Code is Netscape Communications
|
|
# Corporation. Portions created by Netscape are
|
|
# Copyright (C) 1998 Netscape Communications Corporation. All
|
|
# Rights Reserved.
|
|
#
|
|
# Contributor(s): Dave Miller <justdave@bugzilla.org>
|
|
# Frédéric Buclin <LpSolit@gmail.com>
|
|
#%]
|
|
[%
|
|
title = "Attachments"
|
|
desc = "Set up attachment options"
|
|
%]
|
|
|
|
[% param_descs = {
|
|
allow_attachment_display =>
|
|
"If this option is on, users will be able to view attachments from"
|
|
_ " their browser, if their browser supports the attachment's MIME type."
|
|
_ " If this option is off, users are forced to download attachments,"
|
|
_ " even if the browser is able to display them."
|
|
_ "<p>This is a security restriction for installations where untrusted"
|
|
_ " users may upload attachments that could be potentially damaging if"
|
|
_ " viewed directly in the browser.</p>"
|
|
_ "<p>It is highly recommended that you set the <tt>attachment_base</tt>"
|
|
_ " parameter if you turn this parameter on.",
|
|
|
|
attachment_base =>
|
|
"When the <tt>allow_attachment_display</tt> parameter is on, it is "
|
|
_ " possible for a malicious attachment to steal your cookies or"
|
|
_ " perform an attack on $terms.Bugzilla using your credentials."
|
|
_ "<p>If you would like additional security on attachments to avoid"
|
|
_ " this, set this parameter to an alternate URL for your $terms.Bugzilla"
|
|
_ " that is not the same as <tt>urlbase</tt> or <tt>sslbase</tt>."
|
|
_ " That is, a different domain name that resolves to this exact"
|
|
_ " same $terms.Bugzilla installation.</p>"
|
|
_ "<p>Note that if you have set the"
|
|
_ " <a href=\"editparams.cgi?section=advanced#cookiedomain_desc\"><tt>cookiedomain</tt>"
|
|
_" parameter</a>, you should set <tt>attachment_base</tt> to use a"
|
|
_ " domain that would <em>not</em> be matched by"
|
|
_ " <tt>cookiedomain</tt>.</p>"
|
|
_ "<p>For added security, you can insert <tt>%bugid%</tt> into the URL,"
|
|
_ " which will be replaced with the ID of the current $terms.bug that"
|
|
_ " the attachment is on, when you access an attachment. This will limit"
|
|
_ " attachments to accessing only other attachments on the same"
|
|
_ " ${terms.bug}. Remember, though, that all those possible domain names "
|
|
_ " (such as <tt>1234.your.domain.com</tt>) must point to this same"
|
|
_ " $terms.Bugzilla instance.",
|
|
|
|
allow_attachment_deletion => "If this option is on, administrators will be able to delete " _
|
|
"the content of attachments.",
|
|
|
|
maxattachmentsize => "The maximum size (in kilobytes) of attachments to be stored " _
|
|
"in the database. If a file larger than this size is attached " _
|
|
"to ${terms.abug}, $terms.Bugzilla will look at the " _
|
|
"<a href='#maxlocalattachment'><tt>maxlocalattachment</tt> parameter</a> " _
|
|
"to determine if the file can be stored locally on the web server. " _
|
|
"If the file size exceeds both limits, then the attachment is rejected. " _
|
|
"Settings both parameters to 0 will prevent attaching files to ${terms.bugs}.",
|
|
|
|
maxlocalattachment => "The maximum size (in megabytes) of attachments to be stored " _
|
|
"locally on the web server. If set to a value lower than the " _
|
|
"<a href='#maxattachmentsize'><tt>maxattachmentsize</tt> parameter</a>, " _
|
|
"attachments will never be kept on the local filesystem." }
|
|
%]
|