Skip to content
Grav 2.1 is out: every page speaks Markdown. Read the announcement →

How to hide configuration files

first-time

Started by Diego Cabral 4 years ago · 0 replies · 437 views
4 years ago

Hello!

I have inherited a Grav project.
Many files under the /user/config folder (security.yaml, for example) and the /user/accounts.yaml folder are public. That is, any user that knows the right path can access these files on our production server.

Is this expected behaviour? Or did the previous admin make a mistake during configuration?
If this isn't expected, how can I make these pages "private"? I don't think they should be exposed publicly.

Suggested topics

Topic Participants Replies Views Activity
Support · by blu3prince, 4 days ago
1 78 11 hours ago
Support · by complanar, 7 days ago
6 162 2 days ago
Support · by Rick Beebe, 7 days ago
2 121 4 days ago
Support · by alex, 5 days ago
2 103 4 days ago
Support · by Marcel, 2 weeks ago
1 155 5 days ago