summaryrefslogtreecommitdiff
path: root/TWiki
diff options
context:
space:
mode:
authorPeter Thoeny <web-hurd@gnu.org>2001-02-26 20:28:42 +0000
committerPeter Thoeny <web-hurd@gnu.org>2001-02-26 20:28:42 +0000
commit0d4b3589fb559a565edadf0c842a1c7079410e98 (patch)
tree53a7e06ab06f6e18210784aca1dc9986024471b8 /TWiki
parentc6f8c453018058bc79d54a2f8bac2187d616c23b (diff)
none
Diffstat (limited to 'TWiki')
-rw-r--r--TWiki/TWikiAccessControl.mdwn1
1 files changed, 1 insertions, 0 deletions
diff --git a/TWiki/TWikiAccessControl.mdwn b/TWiki/TWikiAccessControl.mdwn
index d43da426..c92f2f9d 100644
--- a/TWiki/TWikiAccessControl.mdwn
+++ b/TWiki/TWikiAccessControl.mdwn
@@ -63,6 +63,7 @@ Define one or both of these variable in the %WEBPREFSTOPIC% topic:
_Notes for read access restriction:_
+* The view restriction is not suitable for very sensitive content since there is a way to circumvent the read access restriction.
* Read access restriction only works if the view script is authenticated, that means that users need to log on also just to read topics. [TWiki Installation](TWikiDocumentation#installation) has more on basic authentication based on the `.htaccess` file.
* There is a workaround if you prefer to to have unrestricted access to view topics located in normal webs, and to authenticate users only for webs where view restriction is enabled:
* Leave the `view` script non authenticated in the `.htaccess` file.