From: Helen B. <he...@ii...> - 2010-01-02 19:24:34
|
At 11:08 PM 2/01/2010, you wrote: >Helen Borrie wrote: > >> I'm glad you mentioned that, as we "borrowed" a directory indexing script when we reconstructed download/prerelease (for which there was no backup). I have the old version of the script that you fixed up so I will compare it with the one in prerelease, in case it's the same one. I'm fairly certain Pavel also duplicated the same script into the 'rabbits' area...not therefore ruling out that this rogue script has been a bit promiscuous! FWIW, the index.php script that you had in manual/pdf was not the same as the one currently in prerelease. >BTW, talking about indexes: we used to have (automatic) indexes off in the server config. Now it's on - see for instance http://firebirdsql.org/devel/doc/manual/. It doesn't hurt there, but there are other places where it might. At the very least, it might reveal the mess we have created in some places :-) > >Do we want this on or off? Off, I think. At least my (often faulty) understanding is that we explicitly index directories that are meant to be accessed via http (such as prerelease and its children) and prevent access to the rest. Helen |