Les commandes ne sont plus passées par un shell dans les Actions, on appelle bash explicitement
This commit is contained in:
parent
fb85a3f792
commit
c1e5577c59
1 changed files with 4 additions and 6 deletions
|
@ -3,19 +3,17 @@
|
||||||
<Group name="secrets-acl">
|
<Group name="secrets-acl">
|
||||||
<Action name="setfacl-secrets" timing="post"
|
<Action name="setfacl-secrets" timing="post"
|
||||||
when="modified" status="check"
|
when="modified" status="check"
|
||||||
command="
|
command="bash -c 'setfacl -m u:www-data:rx /etc/crans/secrets;
|
||||||
setfacl -m u:www-data:rx /etc/crans/secrets;
|
|
||||||
setfacl -m u:www-data:r /etc/crans/secrets/trigger-generate;
|
setfacl -m u:www-data:r /etc/crans/secrets/trigger-generate;
|
||||||
setfacl -m u:www-data:r /etc/crans/secrets/secrets.py /etc/crans/secrets/dhcp.py /etc/crans/secrets/icecast-token"/>
|
setfacl -m u:www-data:r /etc/crans/secrets/secrets.py /etc/crans/secrets/dhcp.py /etc/crans/secrets/icecast-token'"/>
|
||||||
</Group>
|
</Group>
|
||||||
<Action name="setfacl-secrets-freerad" timing="post"
|
<Action name="setfacl-secrets-freerad" timing="post"
|
||||||
when="modified" status="check"
|
when="modified" status="check"
|
||||||
command="
|
command="bash -c 'setfacl -m u:freerad:rx /etc/crans/;
|
||||||
setfacl -m u:freerad:rx /etc/crans/;
|
|
||||||
setfacl -m u:freerad:rx /etc/crans/secrets;
|
setfacl -m u:freerad:rx /etc/crans/secrets;
|
||||||
setfacl -m u:freerad:r /etc/crans/secrets/dhcp.py;
|
setfacl -m u:freerad:r /etc/crans/secrets/dhcp.py;
|
||||||
setfacl -m u:freerad:r /etc/crans/secrets/secrets.py;
|
setfacl -m u:freerad:r /etc/crans/secrets/secrets.py;
|
||||||
setfacl -m u:freerad:r /etc/crans/secrets/trigger-generate.pub;
|
setfacl -m u:freerad:r /etc/crans/secrets/trigger-generate.pub;
|
||||||
setfacl -m m::r /etc/crans/secrets/trigger-generate;
|
setfacl -m m::r /etc/crans/secrets/trigger-generate;
|
||||||
setfacl -m u:freerad:r /etc/crans/secrets/trigger-generate; "/>
|
setfacl -m u:freerad:r /etc/crans/secrets/trigger-generate;'"/>
|
||||||
</Rules>
|
</Rules>
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue