Request to review unblocking of module Fileshare
bengtan - January 18, 2008 - 06:08
I would like to try out fileshare.module, but the module page says that access is denied.
I suspect this is because of security advisory SA-2008-004.
In CVS, it seems that some sort of security related check-in has been committed (http://cvs.drupal.org/viewvc.py/drupal/contributions/modules/fileshare/f...) after the advisory was announced.
Is there a chance we can get a review of fileshare.module so it might be unblocked so we can start using it again? Thanks.
(By the way, I have no idea where is the right place to post this request. Please re route this message as necessary.)

Fixing fileshare
Several people expressed interest in fixing the module fileshare, and they have been given access to the project. When their work is finished, a review will be done. If the review is positive, the module may be republished.
You can still access the module from CVS, see the handbook for details if necessary.
--
The Manual | Troubleshooting FAQ | Tips for posting | How to report a security issue.
It would be very helpful if
It would be very helpful if the rather than just 'access denied', the reason was listed as well as the status. Simply cutting off access to the module and any sort of status update leaves us pretty much in the dark as to what is going on.
Status
Maybe somebody can tell us something about the status.
Access Denied
While I think it's great that people are watching the security of the contributed modules, I think a simple caveat would suffice rather than nannying the potential users of the module.
Especially when after some amount of time here, no word has come as to the module's status. I mean, is it already dead and nobody knows or cares to let the rest of us know?
Several people expressed
and
There's nothing to report; I've not heard of any updates to the module.
--
The Manual | Troubleshooting FAQ | Tips for posting | How to report a security issue.
Would hate to lose the fileshare module
I use it for a repository of files and no one else has permission to upload so I hope that means it is still relatively safe.
The layout of the folders and files has been great I would really hate to start looking for another way to do this as easily as this one. Took me awhile to find this solution.
I also hoped to use this module for minutes of meetings on our Intranet when it moves into Drupal.
To those working on it , thank you and I hope you solve the issues.
Status on Fileshare
Hi,
I am about to create a 120 page Intranet and intend on using fileshare because its a great module which allows one to create sub folders and upload and edit without having to go into the edit view. It would be a shame to see this module disappear.
The client's main purpose is to use the intranet for attachments/documents. I have looked at other file/ upload modules but nothing really compares in terms of funcitonality and simplicity.
Does anyone know of a good substitute that allows subfolder creation or should I just continue to use fileshare.
Being an Intranet we're not really worried about the security issues, just more concerned with reliability esp when we start getting a lot of attahcments.
Also in private mode on an IIS server, when clicking on an attachment we get th error about failing to return and incomplete set of http headers? Is there a patch for this or should we just run apache?
Lastly, perhaps not a fiar question for the developer of this module as he/she hasnt resloved the issue yet, but if i continue to use fileshare now , would i be able to the upgraded version (if this occurs) without having to rebuild everything?
thanks very much,
Ivo
Perth, Australia
folder visibility by authenticated user?
I've spent 2 days testing files systems (even 3rd party options) and the deeper I dig..... the more everything points to the fileshare.module.
Can anyone recommend a file system solution with these 2 pieces of functionality?
1. Create folders
2. Make those folders only visible by authenticated users/profiles (within a role)
EXAMPLE: Image 2 directories (labeled username1 and usernamer2). When Username2 logs in, she can only see the directory "username2" with all the directories and docs within that folder (and not the "username1" folder).
Thank you for any help or pointing me in the right direction.
- regards
I looked at filebrowser --
I looked at filebrowser -- not enough functionality
I looked at web file manager - very unclear if you can get security since you're basically exposing folders in the Drupal root. Does anyone have any insight? Still, I liked the ability to drag and drop to reorder folders and contents.
Does anyone have a better demo running of WFM than the developers?
Any way, another vote for fixing/republishing fileshare. in fact I'm still using it any way since the vulnerability related to uploads and on my application only the admin uploads.
Supporting this request
Please keep this great module alive!
Seconding that support request
I also would like to know what is happening with the fileshare module. I had a support request to post in the issue queue and then found it missing. It's possible that my answer lies in the issue queue, but now it is not even available. what to do?
As I wrote above, there's no
As I wrote above, there's no progress, so, "nothing is happening".
--
The Manual | Troubleshooting FAQ | Tips for posting | How to report a security issue.
Subscribing..
and hoping for a fix, its a great module!
This all seems to be very suspect
Not sure why this module was pulled with no discussion and without any real attempt at analysing how this could be fixed.
Here is something to get the communities conspiracy theory juices flowing. Am I the only one that suspects it is this anything to do with the launch of Acquia.
From my (somewhat limited) understanding, this module should only pose a security threat if you allow anyone other than a trusted admin permission to create a fileshare.
If no-one is allowed to create a fileshare, then they will not be able to access any folder not already authorized.
Who has an opinion on this?
@taldrup I don't know about
@taldrup
I don't know about any conspiracy but I got the same impression about the vulnerability. Considering my site allows all users to add arbitrary PHP into an edit box anyway I'm not so concerned about this problem! For people doing an intranet style site with trusted users this is completely ott. Removing the project removes the ability for users to make contributions and fixes without CVS, plus it takes away the support tracker. There isn't anything to replace this module so whoever reported the issue can fix it! If you know the problem you can work out a solution :|
I'd be happy to take a look at the latest code but it would be nice to be able to access the project to do so.
Possibly Fixed.
I've made an attempt to get the project fixed. I changed the code in HEAD:
http://cvs.drupal.org/viewvc.py/drupal/contributions/modules/fileshare/
I guess I'll contact the security team and see if it's sufficient to get the project back online. Then I'll port the changes to the 5.x and maybe 4.7.x or 6.x...
Thanks, Jamie.
Fingers crossed
I haven't found any suitable alternative to Fileshare and haven't removed it. Nobody has access to publish on my site so I didnt consider it a problem. It is a great module very neat and easy to use, so I am hoping it comes back. Thanks Jamie.
Hope it works
Hope the fileshare module will be unblocked as soon as posslible. Thank you for you work, it is my favorite fileshare module.
Another vote for FileShare
Hi there,
I'm just writing to show my support for FileShare - it's a good module and it'd be great to see it back in service.
Jack Kelly
UKfilm.org - Advice, Discussion and News for the UK filmmaker
Possibly Fixed.
Please update on progress as available.
----
Darly
fileshare for drupal v 6.2
I'm using this module on drupal v 5 and hopefully this will be translated to version 6.
Thanks
"The most important gift we can give the world's children is the gift most likely to lead to future peace and prosperity - and that is the gift of a good education."
Laura Bush - First Lady
http://sunflowermission.org
I'd be happy to port it to
I'd be happy to port it to six if they would re-open the module. I haven't heard a peep from the security team. I'm sure they are busy... just waiting now.
fileshare for drupal v 6.3
I'd just like to add my support for fileshare. I found it really useful for one of my sites and that is now stuck at drupal 5 until Jamie is allowed to upgrade it (best) or I am forced to find a workaround somehow (worst).
Keep up the good work.
Thanks,
John
I'd like to second (or
I'd like to second (or third) the support for fileshare. It's an amazing module.
New Module?
I've been thinking about just re-creating fileshare as a new module with some changes. Perhaps not as a module that creates a new node each time, but as one that can just attach the directory browsing functionality to any node... Don't know if the drupal team would allow that, but what do you all think? I suppose it would have to have a new name... Thoughts?
Jamie.
great idea
i think this sounds like a great idea. it's the slick and intuitive browsing that sets this module apart from other similar solutions. would love it for drupal 5, though.
however, i wouldn't want it to slow you down from getting fileshare available again.
Mark Sanders
Q Collective
The abilty to have a new
The abilty to have a new node for each fileshare was for me one of the main reason to use the module for my downloads. I think this was an absolutely great idea. Btw. have you allready heard something from the security team concerning the unblocking of the module page?
I have not heard anything at
I have not heard anything at all from the security team. :(
If you could attache a fileshare to any node you could still create a new node for each fileshare, they just wouldn't have it's own content type. It's content type could be node, blog, story ... etc whatever you wanted ... if you were running flexinode or cck you could make your own. I was thinking it could be called DirectoryAttach or something... ?
Jamie.
From this point of view: +1
From this point of view: +1 for the idea.
How about Nodefiles?
Nodefiles... not bad. :) I
Nodefiles... not bad. :)
I have to finish off my kids school website, then I'll see if I can't re-start this project.
Thanks for the moral support... ;)