luci-base: ship rpcd uci access ACL
authorJo-Philipp Wich <jo@mein.io>
Sat, 21 Apr 2018 12:59:41 +0000 (14:59 +0200)
committerJo-Philipp Wich <jo@mein.io>
Sat, 21 Apr 2018 12:59:41 +0000 (14:59 +0200)
Ship an ACL definition for granting full read/write access to uci
configuration files via ubus rpc. This is a precondition for enabling
uci session isolation later on.

Signed-off-by: Jo-Philipp Wich <jo@mein.io>
modules/luci-base/root/usr/share/rpcd/acl.d/luci-base.json [new file with mode: 0644]

diff --git a/modules/luci-base/root/usr/share/rpcd/acl.d/luci-base.json b/modules/luci-base/root/usr/share/rpcd/acl.d/luci-base.json
new file mode 100644 (file)
index 0000000..ed7ad8a
--- /dev/null
@@ -0,0 +1,11 @@
+{
+       "uci-access": {
+               "description": "Grant uci write access to all configurations",
+               "read": {
+                       "uci": [ "*" ]
+               },
+               "write": {
+                       "uci": [ "*" ]
+               }
+       }
+}