From 7770785523e54e5f4a5ff2af5b743f8816fa93c7 Mon Sep 17 00:00:00 2001 From: Fol Date: Tue, 22 Jul 2014 15:58:29 +0200 Subject: [PATCH] [Fix] mysql password leak --- scripts/install | 3 +++ scripts/upgrade | 3 +++ 2 files changed, 6 insertions(+) diff --git a/scripts/install b/scripts/install index fc96ddc..b1c5f15 100755 --- a/scripts/install +++ b/scripts/install @@ -56,6 +56,9 @@ echo "Setting permission..." sudo chown -R root: $final_path sudo find $final_path -type f | xargs sudo chmod 644 sudo find $final_path -type d | xargs sudo chmod 755 +# config.inc.php contains sensitive data, restrict its access +sudo chown root:www-data $final_path/config.inc.php +sudo chmod 640 $final_path/config.inc.php # Modify Nginx configuration file and copy it to Nginx conf directory echo "Setting up nginx configuration..." diff --git a/scripts/upgrade b/scripts/upgrade index 92de2cf..f10f818 100644 --- a/scripts/upgrade +++ b/scripts/upgrade @@ -47,6 +47,9 @@ echo "Setting permission..." sudo chown -R root: $final_path sudo find $final_path -type f | xargs sudo chmod 644 sudo find $final_path -type d | xargs sudo chmod 755 +# config.inc.php contains sensitive data, restrict its access +sudo chown root:www-data $final_path/config.inc.php +sudo chmod 640 $final_path/config.inc.php # Modify Nginx configuration file and copy it to Nginx conf directory echo "Setting up nginx configuration..."