default userpic

Security: linked files

Vote 0 Votes

The template options allow you to link to external files, which reside in a directoy of your choice under Site Root. These linked files are obviously valuable in the sense that they contain the product of your design work, and reflect your ability to use Movable Type's templating language.

Is it necessary at all, as a user/administrator of your MT installation, to take any steps to secure (password-protect) a directory with such files on the server?

Reported on Movable Type 4.2

2 Replies

| Add a Reply
  • Let's put it differently: If somebody were about to somehow get all files on your server, how much time would it take - 2 years, or 2 minutes - a degree in computer science or a free tool and some curiosity?

    Does Six Apart offer a word on this topic?

  • It would be a good idea to password protect the directory if you has sensitive information in your templates. Only you can know that for sure, but the default templates, for example, are completely harmless. There's nothing in those that is sensitive.

    All of that said, why link the files underneath the web-accessible part of your server? You can link them anywhere on the entire server? The whole question is rendered moot if you just link them elsewhere.

Add a Reply

If you need to share template code, replace all the "<" signs with "&lt;" or use this utility.

Forum Groups

1773 6162

Last Topic: Excluding categories from blog by kholechek on Feb 9, 2012

86 302

Last Topic: website entries by masoud on Oct 26, 2011

1429 5077

Last Topic: What apocalypse hit this community in the middle of 2011? by 75th on Feb 10, 2012

695 2910

Last Topic: Insert Image / File Fails by Russ Miller on Feb 10, 2012

84 291

Last Topic: How to have some other characters in entry basename automatically written by Afshin Haghighatnia on Dec 22, 2011

173 737

Last Topic: About the MT version stated in HTML source by Alex E. Schneider on Feb 7, 2012

190 567

Last Topic: Analytics Reporting by michael webster on Feb 5, 2012

48 210

Last Topic: An idea and also a request by Afshin Haghighatnia on Jun 29, 2011

64 246

Last Topic: jQuery in MT 5.1 still at 1.4 - why? by perlmonkey on May 25, 2011

code.sixapart.com

137 478

Last Topic: Getting a thumbnail with xpath by Peter on Mar 13, 2011

222 720

Last Topic: Custom Field for Asset Not Appearing by android on Feb 9, 2012