php - Prevent public access to env file -
i found laravel 5 may output sensitive data , can lead further exploitation of many hosts:
https://www.google.com/search?q=intext%3adb_password+ext%3aenv&gws_rd=ssl
i want know way secure .env file. can use below code in .htaccess file protect .env file browser view?
# protect .env <files .env> order allow,deny deny </files> will above code in .htaccess work , protect .env file?
this isn't vulnerability, , isn't remotely issue provided installs laravel correctly - webroot public folder, not repository/project root.
the config files , .env file in laravel not contained in webroot, therefore need ensure webroot path/to/project/public.
the google query provided literally bunch of people didn't read documentation before installing laravel.
Comments
Post a Comment