session management: Allow for restricted shells
Allows the AlternateShell specified by the user in the TS_INFO_PACKET to be passed to startwm.sh as an environment variable.
This commit is contained in:
@@ -45,6 +45,13 @@ RestrictOutboundClipboard=none
|
||||
RestrictInboundClipboard=none
|
||||
; Set to 'no' to prevent users from logging in with alternate shells
|
||||
#AllowAlternateShell=true
|
||||
; Normally, alternate shells (if permitted) are executed directly, as
|
||||
; specified.
|
||||
; If this is set, alternate shells are not actioned directly, but
|
||||
; passed in to the default window manager in the specified environment
|
||||
; variable. This allows the system manager more control over exactly
|
||||
; what alternate shells are permitted.
|
||||
#PassShellAsEnv=XRDP_ALTERNATE_SHELL
|
||||
; On Linux systems, the Xorg X11 server is normally invoked using
|
||||
; no_new_privs to avoid problems if the executable is suid. This may,
|
||||
; however, interfere with the use of security modules such as AppArmor.
|
||||
|
||||
Reference in New Issue
Block a user