From: Ken Coar
Please send any other useful security tips to The Apache Group
diff --git a/docs/manual/mod/mod_userdir.html b/docs/manual/mod/mod_userdir.html
index cca87f5020e..50ac7844658 100644
--- a/docs/manual/mod/mod_userdir.html
+++ b/docs/manual/mod/mod_userdir.html
@@ -33,13 +33,37 @@ is compiled in by default. It provides for user-specific directories.
Status: Base
Module: mod_userdir
Compatibility: All forms except the UserDir
-public_html
form are only available in Apache 1.1 or above.
+public_html form are only available in Apache 1.1 or above. Use +of the enabled keyword, or disabled with a +list of usernames, is only available in Apache 1.3 and above.
The UserDir directive sets the real directory in a user's home directory
to use when a request for a document for a user is received.
-Directory is either disabled
, to disable this feature,
- or the name of a directory, following one of the following
-patterns. If not disabled, then a request for
+Directory/filename is one of the following:
+
+If neither the enabled nor the disabled
+keywords appear in the Userdir directive, the argument is
+treated as a filename pattern, and is used to turn the name into a
+directory specification. A request for
http://www.foo.com/~bob/one/two.html
will be translated to:
UserDir public_html -> ~bob/public_html/one/two.html @@ -52,23 +76,28 @@ UserDir http://www.foo.com/users -> http//www.foo.com/users/bob/one/two.html UserDir http://www.foo.com/*/usr -> http://www.foo.com/bob/usr/one/two.html UserDir http://www.foo.com/~*/ -> http://www.foo.com/~bob/one/two.html- -
- -Be careful when using this directive; for instance, "UserDir -./" would map "/~root" to -"/" - which is probably undesirable. See also -the -<Directory> -directive and the -Security Tips -page for more information. -
++ + Be careful when using this directive; for instance, + "UserDir ./" would map + "/~root" to + "/" - which is probably undesirable. If you are + running Apache 1.3 or above, it is strongly recommended that your + configuration include a + "UserDir disabled root" declaration. + See also + the + <Directory> + directive and the + Security Tips + page for more information. + +