Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow for more portable config.php location #60

Open
jimallman opened this issue Nov 4, 2014 · 1 comment
Open

Allow for more portable config.php location #60

jimallman opened this issue Nov 4, 2014 · 1 comment

Comments

@jimallman
Copy link
Collaborator

Our PHP pages currently assume this is in the parent directory (above all FCDB pages) and that this means it's safe outside the web root. But this will not always match the setup on a given server. We should make the location of config.php configurable or take additional steps to secure it.

@jimallman
Copy link
Collaborator Author

I'm marking this as an enhancement, since we can use an .htaccess file to protect this. Beyond that, our root-relative URLs for images, style, etc. already force the web root to the directory holding all FCDB pages, so this file should fall outside of publicly-accessible space.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant