From: Eric Covener Date: Fri, 27 Mar 2020 16:49:14 +0000 (+0000) Subject: Merge r1875785 from trunk: X-Git-Tag: 2.4.44~155 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=ba82244ca7bccc67376ed5ea806f4533e18ad0a1;p=thirdparty%2Fapache%2Fhttpd.git Merge r1875785 from trunk: add userdir same-origin warnings to mod_userdir Submitted By: Hanno Böck git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1875786 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/docs/manual/mod/mod_userdir.xml b/docs/manual/mod/mod_userdir.xml index d30cd819fb8..0fe76f5f769 100644 --- a/docs/manual/mod/mod_userdir.xml +++ b/docs/manual/mod/mod_userdir.xml @@ -29,6 +29,14 @@ userdir_module +By using this module you are allowing multiple users +to host content within the same origin. The same origin policy is a key +principle of Javascript and web security. By hosting web pages in the same +origin these pages can read and control each other and security issues in +one page may affect another. This is particularly dangerous in combination +with web pages involving dynamic content and authentication and when +your users don't necessarily trust each other. +

This module allows user-specific directories to be accessed using the http://example.com/~user/ syntax.