Bug#565738: drupal: shouldn't enable on all sites by default

2010-11-14 Thread Patrick Matthäi
I agree with Gunnar. This big is not realy security relevant, it would be, if there were open security issues with.. Users could deactivate drupal easily by just removing the symlink and this method is used by several other packages, so that they work after installation. Sure it would be nice to

Bug#565738: drupal: shouldn't enable on all sites by default

2010-09-20 Thread Gunnar Wolf
Matt Taggart dijo [Mon, Sep 20, 2010 at 11:22:51AM -0700]: > IMO it's a security bug, but downgrade if you disagree. > > Thanks, I tend to disagree - And it is a characteristic I really appreciate about Debian's packaging of Drupal: One of those great instances of "Install. It just works." that d

Bug#565738: drupal: shouldn't enable on all sites by default

2010-09-20 Thread Matt Taggart
> Matt, > can you please explain why you think this bug is 'grave' and not just = > 'important'? > > To me, grave definition is: > > makes the package in question unusable or mostly so, or causes data > loss, or introduces a security hole allowing access to the accounts of > users who use the pac

Bug#565738: drupal: shouldn't enable on all sites by default

2010-09-20 Thread Luigi Gangitano
Matt, can you please explain why you think this bug is 'grave' and not just 'important'? To me, grave definition is: makes the package in question unusable or mostly so, or causes data loss, or introduces a security hole allowing access to the accounts of users who use the package and I canno