From 4834c326aa695097add9786645fa252112e9a9f8 Mon Sep 17 00:00:00 2001 From: bruno DA SILVA Date: Wed, 30 Oct 2019 15:45:21 +0100 Subject: [PATCH] 2498 - restrict access to assets into env-* - allow static html into extensions/ and datamodels/ - allow direct access to php into env-* for legacy code taht do not use exec.php --- datamodels/.htaccess | 4 ++-- datamodels/web.config | 6 ++++-- extensions/.htaccess | 4 ++-- extensions/web.config | 6 ++++-- setup/compiler.class.inc.php | 8 ++++++-- 5 files changed, 18 insertions(+), 10 deletions(-) diff --git a/datamodels/.htaccess b/datamodels/.htaccess index 736fc7a95..17ac87ba5 100644 --- a/datamodels/.htaccess +++ b/datamodels/.htaccess @@ -1,7 +1,7 @@ # Apache 2.4 Require all denied - + Require all granted @@ -10,7 +10,7 @@ Require all denied deny from all Satisfy All - + Order Allow,Deny Allow from all diff --git a/datamodels/web.config b/datamodels/web.config index dd0c16efc..a67d0f2d5 100644 --- a/datamodels/web.config +++ b/datamodels/web.config @@ -1,6 +1,6 @@ - + @@ -19,8 +19,10 @@ + + - + \ No newline at end of file diff --git a/extensions/.htaccess b/extensions/.htaccess index 736fc7a95..17ac87ba5 100644 --- a/extensions/.htaccess +++ b/extensions/.htaccess @@ -1,7 +1,7 @@ # Apache 2.4 Require all denied - + Require all granted @@ -10,7 +10,7 @@ Require all denied deny from all Satisfy All - + Order Allow,Deny Allow from all diff --git a/extensions/web.config b/extensions/web.config index dd0c16efc..a67d0f2d5 100644 --- a/extensions/web.config +++ b/extensions/web.config @@ -1,6 +1,6 @@ - + @@ -19,8 +19,10 @@ + + - + \ No newline at end of file diff --git a/setup/compiler.class.inc.php b/setup/compiler.class.inc.php index 68c415e50..be428b748 100644 --- a/setup/compiler.class.inc.php +++ b/setup/compiler.class.inc.php @@ -2932,7 +2932,7 @@ EOF; # Apache 2.4 Require all denied - + Require all granted @@ -2941,7 +2941,7 @@ Require all denied deny from all Satisfy All - + Order Allow,Deny Allow from all @@ -2990,6 +2990,10 @@ EOF; + + + +