From: Eric Covener Date: Fri, 27 Mar 2020 16:48:46 +0000 (+0000) Subject: add userdir same-origin warnings to mod_userdir X-Git-Tag: 2.5.0-alpha2-ci-test-only~1557 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=58adde718cf55de5d182d5d227b4f30cb8ed1035;p=thirdparty%2Fapache%2Fhttpd.git add userdir same-origin warnings to mod_userdir Submitted By: Hanno Böck git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1875785 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/docs/manual/mod/mod_userdir.xml b/docs/manual/mod/mod_userdir.xml index d30cd819fb8..0fe76f5f769 100644 --- a/docs/manual/mod/mod_userdir.xml +++ b/docs/manual/mod/mod_userdir.xml @@ -29,6 +29,14 @@ userdir_module +By using this module you are allowing multiple users +to host content within the same origin. The same origin policy is a key +principle of Javascript and web security. By hosting web pages in the same +origin these pages can read and control each other and security issues in +one page may affect another. This is particularly dangerous in combination +with web pages involving dynamic content and authentication and when +your users don't necessarily trust each other. +

This module allows user-specific directories to be accessed using the http://example.com/~user/ syntax.