default userpic

Security: linked files

Vote 0 Votes

The template options allow you to link to external files, which reside in a directoy of your choice under Site Root. These linked files are obviously valuable in the sense that they contain the product of your design work, and reflect your ability to use Movable Type's templating language.

Is it necessary at all, as a user/administrator of your MT installation, to take any steps to secure (password-protect) a directory with such files on the server?

Reported on Movable Type 4.2

2 Replies

| Add a Reply
  • Let's put it differently: If somebody were about to somehow get all files on your server, how much time would it take - 2 years, or 2 minutes - a degree in computer science or a free tool and some curiosity?

    Does Six Apart offer a word on this topic?

  • It would be a good idea to password protect the directory if you has sensitive information in your templates. Only you can know that for sure, but the default templates, for example, are completely harmless. There's nothing in those that is sensitive.

    All of that said, why link the files underneath the web-accessible part of your server? You can link them anywhere on the entire server? The whole question is rendered moot if you just link them elsewhere.

Add a Reply

If you need to share template code, replace all the "<" signs with "&lt;" or use this utility.

Forum Groups

64 194

Last Topic: movable type 5 custom fields by kljx on Mar 17, 2010

1004 3223

Last Topic: Create Offline Backup by Jackie on Mar 17, 2010

482 1976

Last Topic: ¿Any command line tool to rebuild MT? by Nicolás on Mar 16, 2010

102 360

Last Topic: Saving an entry...what is happening by jdbeast00 on Mar 12, 2010

57 127

Last Topic: Anyone using Disqus with MT5? by Jim S. on Mar 17, 2010

19 69

Last Topic: Custom main index page by Richard on Feb 7, 2010

43 172

Last Topic: by MG on Feb 20, 2010

11 22

Last Topic: Monthly Calendars Help Needed by joe leblanc on Jan 19, 2010

91 326

Last Topic: SpamLookup Keyword Filter 2.1 not work by b.n09 on Nov 17, 2009

55 205

Last Topic: URL Problems by NoSnaiL on Mar 17, 2010

code.sixapart.com

129 448

Last Topic: Action Stream for Google Buzz by jack lail on Feb 16, 2010

160 498

Last Topic: Installed custom Asset markup by spierce on Mar 15, 2010