LTSP Users are allowed to shut down LTSP server

Bug #47834 reported by Jonathan Carter
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
xfce4-session (Ubuntu)
Fix Released
Medium
Unassigned
xubuntu-meta (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Binary package hint: xubuntu-desktop

Users from an LTSP client are able to shut down the server by clicking on log-out, and then on shut down.

LTSP users should not be able to shut down the server.

Revision history for this message
Jani Monoses (jani) wrote :

Can you try to create kiosk files on the server according to
http://www.xfce.org/documentation/docs-4.2/xfce4-session.html#xfsm-kiosk-mode
and see if it helps?

Revision history for this message
Jani Monoses (jani) wrote :

hmm, actually it may need an new upload to fix this, as the logout dialog
talks to HAL directly and does not use the xfce shutdown helper which is inhibited by that settings. I'll think of something else

Revision history for this message
Jani Monoses (jani) wrote :

those kiosk settings may help in not letting users modify the panel or the menu, after removing the quit applet from them.
What should a client be able to do? Logout seems the only harmless action
in the current dialog.

Revision history for this message
Jani Monoses (jani) wrote :

Ok, I have a patch to xfce4-session which makes it not ignore
/etc/xdg/xfce4/kiosk/kioskrc
Having this in the file
[xfce4-session]
Shutdown=%admin

substitute %admin with %anygroup or username
and for the rest only the logout button will be shown (no restart/hibernate etc)

But before a possible upload we should see what else comes up and what the exact requirements are maybe a more general or a cleaner solution is found.

Revision history for this message
Jani Monoses (jani) wrote :

Now xfce4-session correctly observes the kiosk settings so this problem can be handled by the administrator of a thin client setup.

Changed in xubuntu-meta:
status: Unconfirmed → Fix Released
Revision history for this message
Lionel Le Folgoc (mrpouit) wrote :

Closing this bug for xubuntu-meta since it seems it was fixed in xfce4-session.

Changed in xubuntu-meta:
status: New → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.