<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" version="2.0">
  <channel>
    <title>Recent Posts in 'Plugin security' | Beast</title>
    <link>http://forums.scoutapp.com/forums/2/topics/13</link>
    <language>en-us</language>
    <ttl>60</ttl>
    <atom:link href="http://forums.scoutapp.com/open_search.xml" rel="search" type="application/opensearchdescription+xml"/>
    <description></description>
    <item>
      <title>Plugin security replied by rafi @ Thu, 08 May 2008 18:44:36 -0000</title>
      <description>&lt;p&gt;A couple of ideas:&lt;/p&gt;


	&lt;p&gt;A. Have the plugin read the password from a file off the disk. For each machine Scout is monitoring, put that password file somewhere only the Scout client user has access to.&lt;/p&gt;


	&lt;p&gt;B. Set the DB password in an environment variable in the Scout user&amp;#8217;s crontab, or just in the crontab line for Scout. Use the password from env in your plugin script.&lt;/p&gt;</description>
      <pubDate>Thu, 08 May 2008 18:44:36 -0000</pubDate>
      <guid isPermaLink="false">forums.scoutapp.com:2:13:34</guid>
      <author>rafi</author>
      <link>http://forums.scoutapp.com/forums/2/topics/13</link>
    </item>
    <item>
      <title>Plugin security replied by wkoffel @ Wed, 07 May 2008 21:32:17 -0000</title>
      <description>&lt;p&gt;Of course, I found the &amp;#8220;How does Scout approach security?&amp;#8221; mere minutes after posting this. :-)  I think that answers most of my questions.  Still not quote confident that I want DB passwords in my plugins.  Anyone else have a favorite solution to that issue?&lt;/p&gt;</description>
      <pubDate>Wed, 07 May 2008 21:32:17 -0000</pubDate>
      <guid isPermaLink="false">forums.scoutapp.com:2:13:33</guid>
      <author>wkoffel</author>
      <link>http://forums.scoutapp.com/forums/2/topics/13</link>
    </item>
    <item>
      <title>Plugin security replied by wkoffel @ Wed, 07 May 2008 21:23:23 -0000</title>
      <description>&lt;p&gt;What can the admins tell us about plugin security?  For example, I&amp;#8217;d like to execute some DB queries directly in a plugin (not necessary to load my whole Rails environment).  But to do that, I&amp;#8217;d need a DB password in the plugin.&lt;/p&gt;


	&lt;p&gt;I haven&amp;#8217;t sniffed to see, but are the connections that the scout client makes encrypted?&lt;/p&gt;


	&lt;p&gt;How about the security of the plugin store at scoutapp.com?  Would it be inadvisable to store proprietary information in a plugin to be distributed by the scout server?&lt;/p&gt;</description>
      <pubDate>Wed, 07 May 2008 21:23:23 -0000</pubDate>
      <guid isPermaLink="false">forums.scoutapp.com:2:13:32</guid>
      <author>wkoffel</author>
      <link>http://forums.scoutapp.com/forums/2/topics/13</link>
    </item>
  </channel>
</rss>
