[TYPO3-core] RFC #9729: Ship optimal TYPO3 configuration by default

Clemens Riccabona clemens at riccabona.biz
Wed Mar 11 20:53:15 CET 2009


> 
> When we are talking about optimal configuration, should not the we disable
> Indexes for fileadmin by default?
> 
> As TYPO3 has no way to really secure files the need of enabling Indexes
might
> cause a lot of trouble when it concerns
> fileadmin. There we do not have a default .htaccess which says: no, we do
NOT
> want indexes here!
> 
> Uschi (who just encountered this problem!)
> 

This is a problem, yes, but keep in mind: Too much .htaccesses will cause a
slowdown of apache (and most likely any other webserver software).
On good configured Webservers, indexes for directories should be disabled by
default anyway!
If you want this solved by a shipped .htaccess, you should go on stringently
and deny access for t3d, t3x via htaccess, maybe also
tmpl, tpl and ts.
But this should be done within the default configuration of the webserver
too!

Just my 0.5cents



More information about the TYPO3-team-core mailing list