FEATURE: add all directories and files into .htaccess to be prevented from viewing from website

This commit is contained in:
Michal Kváček
2016-04-08 00:13:46 +02:00
parent 5bc077989f
commit 01d9df4dd0
+20 -1
View File
@@ -13,5 +13,24 @@ RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_URI} !^/public/
RewriteRule ^(assets)/(.*)$ public/$1/$2 [L,NC]
#disable viewing all hiden files
# disable viewing all hiden files
RedirectMatch 403 /\..*$
# disable browsing other files in root
RedirectMatch 403 /composer.*
RedirectMatch 403 /artisan
RedirectMatch 403 /phpunit.xml
# disable browsing directories
# this should be solved also with Option -Indexes, however...
RedirectMatch 403 /app
RedirectMatch 403 /artisan
RedirectMatch 403 /bootstrap
RedirectMatch 403 /config
RedirectMatch 403 /database
RedirectMatch 403 /modules
RedirectMatch 403 /resources
RedirectMatch 403 /scripts
RedirectMatch 403 /storage
RedirectMatch 403 /tests
RedirectMatch 403 /vendor