From: Eric Covener Date: Sat, 22 Dec 2012 21:16:09 +0000 (+0000) Subject: caution about merging Location settings on top of directory/files authz config X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=be1fea4a3ec5c435c63611847021d64216fdb142;p=thirdparty%2Fapache%2Fhttpd.git caution about merging Location settings on top of directory/files authz config git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1425345 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/docs/manual/mod/mod_authz_core.html.en b/docs/manual/mod/mod_authz_core.html.en index 740d72b60bd..8b018c98d03 100644 --- a/docs/manual/mod/mod_authz_core.html.en +++ b/docs/manual/mod/mod_authz_core.html.en @@ -500,6 +500,18 @@ Require group admin entire request, and subsequent Require directives are ignored.

+

Security Warning

+

Exercise caution when setting authorization directives in + Location sections + that overlap with content served out of the filesystem. + By default, these configuration sections overwrite authorization configuration + in Directory, + and Files sections.

+

The AuthMerging directive + can be used to control how authorization configuration sections are + merged.

+
+

See also