Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

0.0.2 gem contains files with 0600 modes #6

Open
richardc opened this issue Mar 27, 2018 · 2 comments
Open

0.0.2 gem contains files with 0600 modes #6

richardc opened this issue Mar 27, 2018 · 2 comments

Comments

@richardc
Copy link

$ curl -sO https://rubygems.org/downloads/omniauth-jwt-0.0.2.gem

$ gem unpack omniauth-jwt-0.0.2.gem
Unpacked gem: '/Users/richardc/src/omniauth-jwt-0.0.2'

$ find omniauth-jwt-0.0.2 -ls
8600003236        0 drwxr-xr-x   13 richardc         staff                 416 27 Mar 18:01 omniauth-jwt-0.0.2
8600003241        8 -rw-r--r--    1 richardc         staff                 236 27 Mar 18:01 omniauth-jwt-0.0.2/Guardfile
8600003238        8 -rw-rw-r--    1 richardc         staff                  26 27 Mar 18:01 omniauth-jwt-0.0.2/.rspec
8600003253        0 drwxr-xr-x    4 richardc         staff                 128 27 Mar 18:01 omniauth-jwt-0.0.2/spec
8600003258        8 -rw-rw-r--    1 richardc         staff                 906 27 Mar 18:01 omniauth-jwt-0.0.2/spec/spec_helper.rb
8600003254        0 drwxr-xr-x    3 richardc         staff                  96 27 Mar 18:01 omniauth-jwt-0.0.2/spec/lib
8600003255        0 drwxr-xr-x    3 richardc         staff                  96 27 Mar 18:01 omniauth-jwt-0.0.2/spec/lib/omniauth
8600003256        0 drwxr-xr-x    3 richardc         staff                  96 27 Mar 18:01 omniauth-jwt-0.0.2/spec/lib/omniauth/strategies
8600003257        8 -rw-------    1 richardc         staff                2423 27 Mar 18:01 omniauth-jwt-0.0.2/spec/lib/omniauth/strategies/jwt_spec.rb
8600003243        8 -rw-rw-r--    1 richardc         staff                3211 27 Mar 18:01 omniauth-jwt-0.0.2/README.md
8600003244        8 -rw-rw-r--    1 richardc         staff                 109 27 Mar 18:01 omniauth-jwt-0.0.2/Rakefile
8600003237        8 -rw-rw-r--    1 richardc         staff                 154 27 Mar 18:01 omniauth-jwt-0.0.2/.gitignore
8600003245        0 drwxr-xr-x    3 richardc         staff                  96 27 Mar 18:01 omniauth-jwt-0.0.2/lib
8600003246        0 drwxr-xr-x    5 richardc         staff                 160 27 Mar 18:01 omniauth-jwt-0.0.2/lib/omniauth
8600003248        0 drwxr-xr-x    3 richardc         staff                  96 27 Mar 18:01 omniauth-jwt-0.0.2/lib/omniauth/jwt
8600003249        8 -rw-rw-r--    1 richardc         staff                  61 27 Mar 18:01 omniauth-jwt-0.0.2/lib/omniauth/jwt/version.rb
8600003247        8 -rw-rw-r--    1 richardc         staff                  64 27 Mar 18:01 omniauth-jwt-0.0.2/lib/omniauth/jwt.rb
8600003250        0 drwxr-xr-x    3 richardc         staff                  96 27 Mar 18:01 omniauth-jwt-0.0.2/lib/omniauth/strategies
8600003251        8 -rw-------    1 richardc         staff                1552 27 Mar 18:01 omniauth-jwt-0.0.2/lib/omniauth/strategies/jwt.rb
8600003240        8 -rw-rw-r--    1 richardc         staff                  97 27 Mar 18:01 omniauth-jwt-0.0.2/Gemfile
8600003242        8 -rw-rw-r--    1 richardc         staff                1071 27 Mar 18:01 omniauth-jwt-0.0.2/LICENSE.txt
8600003239        8 -rw-rw-r--    1 richardc         staff                  63 27 Mar 18:01 omniauth-jwt-0.0.2/.travis.yml
8600003252        8 -rw-rw-r--    1 richardc         staff                1188 27 Mar 18:01 omniauth-jwt-0.0.2/omniauth-jwt.gemspec

The problematic file there is omniauth-jwt-0.0.2/lib/omniauth/strategies/jwt.rb. It's 0600 which means if I install it as a system gem only the user who installed it can use it.

Could you ship a 0.0.3 with that permission corrected? Thanks

@blackst0ne
Copy link

Came here to upvote this issue.
Please, fix it.

pboling referenced this issue in pboling/omniauth-jwt2 Nov 30, 2023
Updates the Zendesk SSO article linked in the README which
is currently broken.
pboling referenced this issue in pboling/omniauth-jwt2 Nov 30, 2023
Updates the Zendesk SSO article linked in the README which
is currently broken.
@pboling
Copy link

pboling commented Mar 7, 2024

FYI: I rewrote this gem and modernized it!

https://github.com/pboling/omniauth-jwt2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants