[GH-ISSUE #186] Potential security problem when checking authdb acessibility #118

Closed
opened 2026-02-28 01:21:04 +03:00 by kerem · 1 comment
Owner

Originally created by @bajizs on GitHub (Oct 9, 2018).
Original GitHub issue: https://github.com/tuxis-ie/nsedit/issues/186

github.com/tuxis-ie/nsedit@371eb41787/index.php (L39)

Not a good solution to send to browser (any user) where is the user database file. For example You move the database out of web folder, for better security, and You send information to user where is it.

If You want to make this test, better to test over self connection to the server, or check first it is in web folder or not.

Originally created by @bajizs on GitHub (Oct 9, 2018). Original GitHub issue: https://github.com/tuxis-ie/nsedit/issues/186 https://github.com/tuxis-ie/nsedit/blob/371eb417871c4e37293b84f5dda235dc40953987/index.php#L39 Not a good solution to send to browser (any user) where is the user database file. For example You move the database out of web folder, for better security, and You send information to user where is it. If You want to make this test, better to test over self connection to the server, or check first it is in web folder or not.
kerem closed this issue 2026-02-28 01:21:04 +03:00
Author
Owner

@vahem2lu commented on GitHub (Nov 24, 2020):

Maybe merge?

<!-- gh-comment-id:732974884 --> @vahem2lu commented on GitHub (Nov 24, 2020): Maybe merge?
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nsedit#118
No description provided.