Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-17149

Unjustified security warning about debug log file being downloadable

    Details

    • Documentation Required?:
      None
    • Funding Source:
      Contributed Code

      Description

      Setting the CiviCRM debug log outside of the web root is best practices. Yet when you do so you are greeted with a warning message about this debug log being downloadable.

      This is because the current security checks code assumes that the debug log is somewhere under the 'files' directory in Drupal/WordPress and does not check otherwise.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                nganivet Nicolas Ganivet
                Reporter:
                nganivet Nicolas Ganivet
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 5 minutes
                  5m
                  Remaining:
                  Remaining Estimate - 5 minutes
                  5m
                  Logged:
                  Time Spent - Not Specified
                  Not Specified