httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Brian Behlendorf <br...@hyperreal.org>
Subject Re: cvs commit: apache-1.3/src/modules/standard mod_rewrite.c
Date Fri, 22 May 1998 02:47:27 GMT
At 07:42 PM 5/21/98 -0600, you wrote:
>"the" default Apache config _does_ have it enabled from a quick glance.
>
>It allows ~userdir requests, and doesn't have an Options setting for user
>dirs which means they get Options All.

Ah, right.  We could fix this before 1.3.0.  There are a number of ways:

1) don't enable mod_userdir in default Configuration.tmpl
   Ick, I think people would submit bug reports about it 
   being missing.

2) comment out UserDir directive in srm.conf-dist
   Better, but it doesn't address the lack of security 
   contexts.

3) put a <Directory /> section in access.conf-dist with very restrictive
   set of permissions, and detail in the installation pages how to add
   permissions for different directories.

	Brian


--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--
pure chewing satisfaction                                  brian@apache.org
                                                        brian@hyperreal.org

Mime
View raw message