in reply to Re^4: Using relative paths with taint mode
in thread Using relative paths with taint mode
as they are still accessible through HTTP as prod/ is the web root.
Why is that so? Do you understand the purpose of "web root"? Please clean that up: neither cgi-bin nor lib are supposed to lie under the web root (nor are templates). Also, an index.html doesn't make anything inaccessible, it just gets served when a browser is pointed to the directory (in a typical configuration).
I mean, of course you can fiddle with as many of .htaccess files as you like, but why not simply avoid the problem in the first place?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^6: Using relative paths with taint mode
by Bod (Parson) on Jun 21, 2021 at 22:45 UTC | |
by haj (Vicar) on Jun 22, 2021 at 12:52 UTC | |
by Bod (Parson) on Jun 25, 2021 at 17:26 UTC | |
by afoken (Chancellor) on Jun 24, 2021 at 07:55 UTC |