Skip to content
Grav 2.0 is officially stable. Read the announcement →
Support

How to hide configuration files

first-time

Started by Diego Cabral 4 years ago · 0 replies · 408 views
4 years ago

Hello!

I have inherited a Grav project.
Many files under the /user/config folder (security.yaml, for example) and the /user/accounts.yaml folder are public. That is, any user that knows the right path can access these files on our production server.

Is this expected behaviour? Or did the previous admin make a mistake during configuration?
If this isn't expected, how can I make these pages "private"? I don't think they should be exposed publicly.

Suggested topics

Topic Participants Replies Views Activity
Support · by Paul Hodges, 4 weeks ago
19 489 6 days ago
Support · by Lauw, 1 week ago
2 106 7 days ago
Support · by Anna, 3 weeks ago
4 428 1 week ago
Support · by gtx, 4 weeks ago
4 379 3 weeks ago
Support · by Anna, 1 month ago
9 487 4 weeks ago