Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-21571

Create .htaccess supporting both Apache 2.4 and 2.0-2.2 versions

    Details

    • Type: Improvement
    • Status: Open
    • Priority: Trivial
    • Resolution: Unresolved
    • Affects Version/s: 4.7.28
    • Fix Version/s: None
    • Component/s: Core CiviCRM
    • Versioning Impact:
      Patch (backwards-compatible bug fixes)
    • Documentation Required?:
      Developer Doc
    • Funding Source:
      Contributed Code
    • Verified?:
      Yes
    • How it works currently:
      Files on newer Apache versions in secured folders (e.g. upload) can be accessed without proper authorization.
    • How it should work:
      Secured folders (e.g. upload) should be accessed with proper authorization, independent from the version of apache.

      Description

      The current .htaccess file is set up for Apache versions 2.2 and earlier. This causes security issues when the server/hosting company only supports newer versions, i.e. 2.4 and higher. In this case the old commands will not affect access.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              edvanleeuwen Ed van Leeuwen
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:

                Time Tracking

                Estimated:
                Original Estimate - 1 hour
                1h
                Remaining:
                Remaining Estimate - 1 hour
                1h
                Logged:
                Time Spent - Not Specified
                Not Specified