Last modified: 2012-04-12 14:00:09 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T26133, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 24133 - generated LocalSettings.php should not be world-readable
generated LocalSettings.php should not be world-readable
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
Installer (Other open bugs)
1.16.x
PC Linux
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2010-06-26 22:06 UTC by Jonathan Wiltshire
Modified: 2012-04-12 14:00 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Jonathan Wiltshire 2010-06-26 22:06:30 UTC
Forwarded from Debian (http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550940):

After running the web-based initial configuration of mediawiki
(/var/lib/mediawiki/config/index.php), it created a LocalSettings.php
and instructed me to place it in /etc/mediawiki:

~$ ls -l /etc/mediawiki/LocalSettings.php
-rw-rw-rw- 1 www-data www-data 4536 14 okt 10.54 /etc/mediawiki/LocalSettings.php

This file contains MySQL passwords and should therefore not be world-readable.

I notice that README.Debian suggests changing this, but the file
should not be created world-readable in the first place.
Comment 1 Chad H. 2010-07-26 19:03:14 UTC
Fixed in r69322. We don't write LocalSettings.php to the webserver at all in the new installer.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links