diff options
author | Jo-Philipp Wich <jo@mein.io> | 2020-04-09 22:52:37 +0200 |
---|---|---|
committer | Jo-Philipp Wich <jo@mein.io> | 2020-04-09 23:23:33 +0200 |
commit | c099344013ad72d01a93b99184c72c5eeb792174 (patch) | |
tree | c01d65714fe1813b689151a31d370baca498f971 /applications/luci-app-firewall/root | |
parent | 1e07e3a52d4d06cc82ab07f2b7fbba0a9a6fb801 (diff) |
treewide: reorganize base ACLs
Signed-off-by: Jo-Philipp Wich <jo@mein.io>
Diffstat (limited to 'applications/luci-app-firewall/root')
-rw-r--r-- | applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-firewall.json | 24 | ||||
-rw-r--r-- | applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-openvpn.json | 11 |
2 files changed, 24 insertions, 11 deletions
diff --git a/applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-firewall.json b/applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-firewall.json new file mode 100644 index 000000000..0ee29ad21 --- /dev/null +++ b/applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-firewall.json @@ -0,0 +1,24 @@ +{ + "luci-app-firewall": { + "description": "Grant access to firewall configuration", + "read": { + "file": { + "/etc/firewall.user": [ "read" ] + }, + "ubus": { + "file": [ "read" ], + "luci": [ "getConntrackHelpers" ] + }, + "uci": [ "firewall" ], + }, + "write": { + "file": { + "/etc/firewall.user": [ "write" ] + }, + "ubus": { + "file": [ "write" ] + }, + "uci": [ "firewall" ] + } + } +} diff --git a/applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-openvpn.json b/applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-openvpn.json deleted file mode 100644 index bc9d8e184..000000000 --- a/applications/luci-app-firewall/root/usr/share/rpcd/acl.d/luci-app-openvpn.json +++ /dev/null @@ -1,11 +0,0 @@ -{ - "luci-app-openvpn": { - "description": "Grant file upload access to /etc/openvpn", - "write": { - "cgi-io": [ "upload" ], - "file": { - "/etc/openvpn/*": [ "write" ] - } - } - } -} |