Prevent unauthorized access to RDP files and icons #68
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR adds logic to
get-image.aspxandget-rdp.aspxthat requires the currently authenticated user to have access to the rdp/icon file for it to be served. Since all users have read access to C:\inetpub by default, all RDP and image files will also be available to any user by default. RAWeb installations that use anonymous authentication are also supported (as long as the IUSR user can access the RDP/image files). With this PR, the multiuser permisisons functionality described in the wiki is restored.This PR also modifies the setup script to remove anonymous authentication on the resources and multuser-resources folders. To prevent access to restricted resources, resources should only be accessible via
get-image.aspxandget-rdp.aspx.Tested webfeed scenarios
resourcesfolderresourcesmultiuser-resourcesfoldermultiuser-resources/usersmultiuser-resources/usersmultiuser-resources/groupsmultiuser-resources/groupTested clients