fatfree
fatfree copied to clipboard
The nginx sample config security issue
The sample nginx setup should include the rule to block all .ini
files.
normally you won't place them in the www-folder, would you?
The apache htaccess file in the project does include the directive to prevent the server from serving ini files, why not included the same for the nginx example?
The same applies to the tmp directory which is within the docroot.