Skip to content

Conversation

@chris2286266
Copy link

Fixed the security issue with readable config.txt file.
It is replaces by config.php, which could be executed but exits immediately and does NOT disclose security critical information (e.g. rpcuser and rpcpassword).

Switching from highly unsecure usage of config.txt to config.php
Based on config-example.txt
Configuration implemented as php file now, which is NOT displayed as the txt file before.
Fixed the security issue with readable config.txt file by replacing it with config.php
No longer needed, replaced by config-example.php
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant