From a37c3ea5f2f59f375302217ac4ecd4ff294d0667 Mon Sep 17 00:00:00 2001 From: Tymoteusz Motylewski <t.motylewski@gmail.com> Date: Fri, 9 Feb 2018 10:14:24 +0100 Subject: [PATCH] [TASK] Block access to .typoscript files As .typoscript is the preferred file ending for TypoScript files, this should be reflected in the .htaccess access rules as well. Change-Id: If894d831afb5fd7e3ed1c098023111b82cde124f Resolves: #83703 Releases: 7.6 Reviewed-on: https://review.typo3.org/55626 Tested-by: TYPO3com <no-reply@typo3.com> Reviewed-by: Oliver Klee <typo3-coding@oliverklee.de> Reviewed-by: Reiner Teubner <rteubner@me.com> Reviewed-by: Mathias Schreiber <mathias.schreiber@typo3.com> Tested-by: Mathias Schreiber <mathias.schreiber@typo3.com> Reviewed-by: Christian Kuhn <lolli@schwarzbu.ch> Tested-by: Christian Kuhn <lolli@schwarzbu.ch> --- _.htaccess | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_.htaccess b/_.htaccess index 679693fc4bd7..b0028c41b7ba 100644 --- a/_.htaccess +++ b/_.htaccess @@ -310,7 +310,7 @@ AddDefaultCharset utf-8 </IfModule> # Access block for files -<FilesMatch "(?i:^\.|^#.*#|^(?:ChangeLog|ToDo|Readme|License)(?:\.md|\.txt)?|^composer\.(?:json|lock)|^ext_conf_template\.txt|^ext_typoscript_constants\.txt|^ext_typoscript_setup\.txt|flexform[^.]*\.xml|locallang[^.]*\.(?:xml|xlf)|\.(?:bak|co?nf|cfg|ya?ml|ts|dist|fla|in[ci]|log|sh|sql(?:\..*)?|sw[op]|git.*)|.*(?:~|rc))$"> +<FilesMatch "(?i:^\.|^#.*#|^(?:ChangeLog|ToDo|Readme|License)(?:\.md|\.txt)?|^composer\.(?:json|lock)|^ext_conf_template\.txt|^ext_typoscript_constants\.txt|^ext_typoscript_setup\.txt|flexform[^.]*\.xml|locallang[^.]*\.(?:xml|xlf)|\.(?:bak|co?nf|cfg|ya?ml|ts|typoscript|dist|fla|in[ci]|log|sh|sql(?:\..*)?|sw[op]|git.*)|.*(?:~|rc))$"> # Apache < 2.3 <IfModule !mod_authz_core.c> Order allow,deny -- GitLab