From 58adde718cf55de5d182d5d227b4f30cb8ed1035 Mon Sep 17 00:00:00 2001 From: Eric Covener Date: Fri, 27 Mar 2020 16:48:46 +0000 Subject: [PATCH] add userdir same-origin warnings to mod_userdir MIME-Version: 1.0 Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit Submitted By: Hanno Böck git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1875785 13f79535-47bb-0310-9956-ffa450edef68 --- docs/manual/mod/mod_userdir.xml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/docs/manual/mod/mod_userdir.xml b/docs/manual/mod/mod_userdir.xml index d30cd819fb8..0fe76f5f769 100644 --- a/docs/manual/mod/mod_userdir.xml +++ b/docs/manual/mod/mod_userdir.xml @@ -29,6 +29,14 @@ userdir_module +By using this module you are allowing multiple users +to host content within the same origin. The same origin policy is a key +principle of Javascript and web security. By hosting web pages in the same +origin these pages can read and control each other and security issues in +one page may affect another. This is particularly dangerous in combination +with web pages involving dynamic content and authentication and when +your users don't necessarily trust each other. +

This module allows user-specific directories to be accessed using the http://example.com/~user/ syntax.

-- 2.47.3