Viewing 4 replies - 1 through 4 (of 4 total)
  • Thread Starter russwiltshire

    (@russwiltshire)

    Thanks, but no that doesn’t help. I already read and followed those instructions. Those instructions are exactly what I’m suggesting are not secure. They suggest creating a service account with Storage Admin permissions. So the credentials in the wp-stateless settings could be used by anyone to connect to my GCP Cloud Storage. For example, if I set up a WordPress site for one of my customers, set up wp-stateless as per those instructions, then give my customer access to their wp-admin area, they would be able to see the wp-stateless settings, change the bucket name or folder name to something else, and their WP site would then have access to someone else’s files.

    You can only give Read and Wright permission, that way they wouldn’t be able to any administrative task. But there is no way to restrict permission to a folder. You can create separate Storage for every site.

    Thread Starter russwiltshire

    (@russwiltshire)

    Ok. Thank you. That’s what I’ve ended up doing. Create a bucket and service account for each site. Good to know I’m not missing something.

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Is the security a bit too open here?’ is closed to new replies.