attachment.html.tmpl 3.51 KB
Newer Older
1 2 3
[%# This Source Code Form is subject to the terms of the Mozilla Public
  # License, v. 2.0. If a copy of the MPL was not distributed with this
  # file, You can obtain one at http://mozilla.org/MPL/2.0/.
4
  #
5 6
  # This Source Code Form is "Incompatible With Secondary Licenses", as
  # defined by the Mozilla Public License, v. 2.0.
7 8 9 10 11 12 13
  #%]
[%
   title = "Attachments"
   desc = "Set up attachment options"
%]

[% param_descs = {
14 15 16 17 18 19 20 21
  allow_attachment_display =>
    "If this option is on, users will be able to view attachments from"
    _ " their browser, if their browser supports the attachment's MIME type."
    _ " If this option is off, users are forced to download attachments,"
    _ " even if the browser is able to display them."
    _ "<p>This is a security restriction for installations where untrusted"
    _ " users may upload attachments that could be potentially damaging if"
    _ " viewed directly in the browser.</p>"
22
    _ "<p>It is highly recommended that you set the <var>attachment_base</var>"
23 24 25
    _ " parameter if you turn this parameter on.",

  attachment_base => 
26
    "When the <var>allow_attachment_display</var> parameter is on, it is "
27
    _ " possible for a malicious attachment to steal your cookies or"
28
    _ " perform an attack on Bugzilla using your credentials."
29
    _ "<p>If you would like additional security on attachments to avoid"
30
    _ " this, set this parameter to an alternate URL for your Bugzilla"
31
    _ " that is not the same as <var>urlbase</var> or <var>sslbase</var>."
32
    _ " That is, a different domain name that resolves to this exact"
33
    _ " same Bugzilla installation.</p>"
34
    _ "<p>Note that if you have set the"
35 36
    _ " <a href=\"editparams.cgi?section=advanced#cookiedomain_desc\"><var>cookiedomain</var>"
    _" parameter</a>, you should set <var>attachment_base</var> to use a"
37
    _ " domain that would <em>not</em> be matched by"
38 39
    _ " <var>cookiedomain</var>.</p>"
    _ "<p>For added security, you can insert <var>%bugid%</var> into the URL,"
40 41 42 43
    _ " which will be replaced with the ID of the current $terms.bug that"
    _ " the attachment is on, when you access an attachment. This will limit"
    _ " attachments to accessing only other attachments on the same"
    _ " ${terms.bug}. Remember, though, that all those possible domain names "
44
    _ " (such as <kbd>1234.your.domain.com</kbd>) must point to this same"
45
    _ " Bugzilla instance.",
46

47 48 49
  allow_attachment_deletion => "If this option is on, administrators will be able to delete " _
                               "the content of attachments.",

50 51
  maxattachmentsize => "The maximum size (in kilobytes) of attachments to be stored " _
                       "in the database. If a file larger than this size is attached " _
52
                       "to ${terms.abug}, Bugzilla will look at the " _
53
                       "<a href=\"#maxlocalattachment\"><var>maxlocalattachment</var> parameter</a> " _
54 55 56
                       "to determine if the file can be stored locally on the web server. " _
                       "If the file size exceeds both limits, then the attachment is rejected. " _
                       "Settings both parameters to 0 will prevent attaching files to ${terms.bugs}.",
57

58 59
  maxlocalattachment => "The maximum size (in megabytes) of attachments to be stored " _
                        "locally on the web server. If set to a value lower than the " _
60
                        "<a href=\"#maxattachmentsize\"><var>maxattachmentsize</var> parameter</a>, " _
61
                        "attachments will never be kept on the local filesystem." }
62
%]