Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think that the plugin should declare it's behavior. Consider the case were you have a shared webserver and a php-plugin for one user (say a wordpress installation). Then the user ( or anyone with write access to the user directory) can control the permissions of the server.

On the other hand, a well designed plugin interface could set default permissions. For example the plugin interface could have a SQL method, so that a plugin does not need to talk to a socket directly.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: