]> sipb.mit.edu Git - ikiwiki.git/commitdiff
note that the patch on this page is complely broken, and allows any file starting...
authorJoey Hess <joey@gnu.kitenet.net>
Sun, 14 Mar 2010 19:08:41 +0000 (15:08 -0400)
committerJoey Hess <joey@gnu.kitenet.net>
Sun, 14 Mar 2010 19:08:41 +0000 (15:08 -0400)
If you applied that patch to your site, you should remove it right away!

doc/todo/enable-htaccess-files.mdwn

index c895db75dbcceaf3f95b3ae999919db30f67f822..c08502bdd6cefc80173d86dc72701e5c9cd52a79 100644 (file)
                     qr/(^|\/).svn\//, qr/.arch-ids\//, qr/{arch}\//],
            wiki_link_regexp => qr/\[\[(?:([^\]\|]+)\|)?([^\s\]#]+)(?:#([^\s\]]+))?\]\]/,
 
+> Note that the above patch is **completely broken**. 
+> It removes the crucial excludes of all files starting with a dot.
+> The negative regexps for htaccess have no effect, so the whole
+> thing only "works" because it allows *any* file starting with a dot.
+> If you applied this patch to your ikiwiki, you opened a huge security
+> hole. --[[Joey]] 
+
 [[!tag patch patch/core]]
 
 This lets the site administrator have a `.htaccess` file in their underlay