Permissions on Uberspace
Because of a small mistake, I had overwritten all permissions in the directory /var/www/virtual/username.
How do you set everything right again?
cd /var/www/virtual/$USER
# Rechte für Ordner (type = directory) (rwxr-xr-x)
find * -type d -print0 | xargs -0 chmod 755
# Rechte für Dateien (type = file) (rw-r--r--)
find * -type f -print0 | xargs -0 chmod 644
# FCGI-Scripte müssen ausführbar sein
chmod 700 fcgi-bin/*
# Der Ordner . also /var/www/virtual/$USER sollte die Rechte 750 haben, also
ll /var/www/virtual | grep $USER
# drwxr-x--- 18 username apache 4096 3. Jul 16:06 usernameThe important thing is that the web server (group: apache) can read all files. (PHP scripts run as FCGI scripts under your user account, but all other files, such as static images, are read and forwarded directly by the web server (apache).)
/var/www/virtual/$USER belongs to the group apache and grants the group read permissions
/var/www/virtual/$USER/html grants execute/search permissions (x) to others (and therefore apache)
/var/www/virtual/$USER/html/.htaccess grants read permissions (r) to others (and therefore apache)In addition, for security reasons, FCGI scripts must not grant write permissions to the group or to others, while your user must be able to execute them (e.g. 700, rwx———).
The read permissions granted to others for all other files do not pose a security problem, since other snooping users are already locked out at the directory
/var/www/virtual/$USERA brief overview of the permission system in Linux:
For every file, read permissions (r), write permissions (w), and execute/search permissions (x) can be set separately for a user, a group, and others (that is, everyone who is neither the user nor a member of the group). For files, x means that the file can be executed directly and corresponds to the .exe extension in Windows. For directories, x determines whether someone is allowed to access the directory's contents.
ls -l irgendein_Ordner
-rw-r--r-- 1 peter gedoens 418 28. Okt 2013 datei1.txt
-rwxrwxrwx 1 peter gedoens 418 28. Okt 2013 datei-die-jeder-bearbeiten-
und-ausführen-kann.sh
-rw-r--r-- 1 peter gedoens 418 28. Okt 2013 datei-ohne-endung
|\ /\ /\ /
| | | |
| | | |-- o Rechte für jeden, der nicht der User peter ist
| | | oder der Gruppe gedoens angehört.
| | |----- g Rechte für Mitglieder der Gruppe gedoens.
| |-------- u Rechte für den User peter, der damit auch
| Besitzer der Datei oder des Ordners ist.
|---------- Typ des Elements, meist d für Ordner oder
f für Dateien. (l für Links, c für character
devices, siehe /dev, s für gesetztes suid bit)What do the numbers mean, e.g. 755 or 750?
The numbers are simply another way of writing the rwxrwxrwx notation. Divide rwxrwxrwx into three groups of three and assign numbers to the positions:
rwx rwx rwx
421 421 421Now simply add the corresponding numbers for the permissions you want to enable, e.g.
r = 4 rw = 6 x = 1 rwx = 7 rx = ?If you do not want to memorize this, the chmod command, which changes permissions, also accepts the following notation:
chmod o-r irgendeine-datei.txtInstead of absolute 755, relative changes also work: + means adding permissions, – means removing permissions, and = means setting permissions.
Before +, =, or - comes u, g, or o for user, group, or other. After +, =, or - come the permissions, namely r, w, or x.
Examples: uo+w o-rwx u+w ugo+rwx u=rwx u+r,g=r
I want to grant 3 people write permissions and a 4th person read permissions
For normal use by an individual, this permission-management principle is relatively easy to understand, manageable, and—despite its many limitations—sufficient. However, anyone managing many users can use ACLs, which allow permissions to be distributed much more finely among many users: http://www.knilse.de/download/acl.html