]> scripts.mit.edu Git - www/ikiwiki.git/blobdiff - doc/todo/enable-htaccess-files.mdwn
note that the patch on this page is complely broken, and allows any file starting...
[www/ikiwiki.git] / doc / todo / enable-htaccess-files.mdwn
index c895db75dbcceaf3f95b3ae999919db30f67f822..c08502bdd6cefc80173d86dc72701e5c9cd52a79 100644 (file)
                     qr/(^|\/).svn\//, qr/.arch-ids\//, qr/{arch}\//],
            wiki_link_regexp => qr/\[\[(?:([^\]\|]+)\|)?([^\s\]#]+)(?:#([^\s\]]+))?\]\]/,
 
+> Note that the above patch is **completely broken**. 
+> It removes the crucial excludes of all files starting with a dot.
+> The negative regexps for htaccess have no effect, so the whole
+> thing only "works" because it allows *any* file starting with a dot.
+> If you applied this patch to your ikiwiki, you opened a huge security
+> hole. --[[Joey]] 
+
 [[!tag patch patch/core]]
 
 This lets the site administrator have a `.htaccess` file in their underlay