[dokuwiki] Re: permissions and dokuwiki.txt

  • From: Chris Tapp <opensource@xxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Tue, 10 Jan 2012 22:22:34 +0000

On 10 Jan 2012, at 21:53, Don Shesnicky wrote:

I'm running a fresh install and yum updated Centos 5 linux server with apache and php. I downloaded the latest stable dokuwiki Rincewind, tar -xzf'ed it into /var/www/html and then created a /var/ www/html/wiki link to the dokuwiki-2011-05-25 directory. After running the install.php script I can access the http://yourserver/wiki/data/pages/wiki/dokuwiki.txt file which I apparently should not be able to do. Not that I think it should affect this but I can access that file even if I install as a closed wiki. The issue isn't closed or not closed but the deeper one that the file can be accessed at all.

I figure I can fix that one file but I'm more concerned that the install.php script, which is suppose to check for needed file permissions, didn't correctly do something. Is that true or do I need to shutdown the permissions down further after the installer has run?

The data/pages/wiki directory is 755 and that particular file is 644.

Don

Have a look at http://www.dokuwiki.org/security. That should explain what you need to do. I use the LocationMatch option with a virtual host under CentOS 5 and 6.

Chris Tapp

opensource@xxxxxxxxxxxx
www.keylevel.com



--
DokuWiki mailing list - more info at
http://www.dokuwiki.org/mailinglist

Other related posts: