customBuild via web interface - FLUID-2937 - still requesting review

Laurel A. Williams laurel.williams at
Tue Aug 25 19:19:31 UTC 2009

Hi all,

Still hoping that I can get a review of the patch to build.xml as noted 
below. I'm not even sure if we want to commit this patch as it is only 
needed for the server version of customBuild, but it would be worth 
someone looking at it and commenting.


Laurel A. Williams wrote:
> Hi all,
> I have been working on the challenge of executing the customBuild ant 
> script via a web interface. There have been some barriers due to file 
> permissions and maven settings defaults.
> I have made considerable progress on modifying the build.xml to run a 
> custom script calling Maven, and have posted some thoughts, a script 
> file and a new patch at
> I have recorded some of my concerns in the JIRA. In particular, I had 
> to open up execute permissions to all users on the custom script, and 
> write permissions to all users in the .m2 directory and the infusion 
> directory. I'm pretty sure I'm opening up security holes that we would 
> prefer not to have...and would appreciate some advice on ways to lock 
> things down better.
> In addition, I am not sure what concerns we may have about multiple 
> users attempting to access ant, maven and the script at the same time. 
> This is more of a unix thing that I don't know that much about yet - 
> can multiple users execute the same commands via the web page safely?? 
> I'm sure someone on this list knows but I'm not clear on it.
> Would appreciate some feedback from Colin and Jamon and anyone else 
> who has thoughts.
> Laurel
> _______________________________________________________
> fluid-work mailing list - fluid-work at
> To unsubscribe, change settings or access archives,
> see
-------------- next part --------------
A non-text attachment was scrubbed...
Name: laurel_williams.vcf
Type: text/x-vcard
Size: 269 bytes
Desc: not available
URL: <>

More information about the fluid-work mailing list