Bug#1072729: Acknowledgement (apache2: misleading comment in default /etc/apache2/apache2.conf about accessibility of root filesystem)

2024-06-10 Thread Oliver Weihe
Hi again, similar issue with .htaccess and .htpasswd - a simple symlink and Apache happily serves the file(s) so the following lines don't really prevent this. --- 8< --- # # The following lines prevent .htaccess and .htpasswd files from being # viewed by Web clients. # Require all de

Bug#1072729: apache2: misleading comment in default /etc/apache2/apache2.conf about accessibility of root filesystem

2024-06-07 Thread Oliver Weihe
Package: apache2 Version: 2.4.59-1~deb12u1 Hi, I *think* the comment above the directive is misleading in the default /etc/apache2/apache2.conf: --- 8< --- # Sets the default security model of the Apache2 HTTPD server. It does # not allow access to the root filesystem outside of /usr/share a