mirror of
https://github.com/YunoHost/package_check.git
synced 2024-09-03 20:06:20 +02:00
Add an error message when /var/www/ is world-readable/enterable
This commit is contained in:
parent
1b3f2fba0f
commit
763f293531
1 changed files with 7 additions and 1 deletions
|
@ -85,6 +85,12 @@ _INSTALL_APP () {
|
|||
|
||||
local ret=$?
|
||||
[ $ret -eq 0 ] && log_debug "Installation successful." || log_error "Installation failed."
|
||||
|
||||
if LXC_EXEC "su nobody -s /bin/bash -c 'test -r /var/www/$app_id || test -w /var/www/$app_id || test -x /var/www/$app_id'"
|
||||
then
|
||||
log_error "It looks like anybody can read/enter /var/www/$app_id, which ain't super great from a security point of view ... Config files or other files may contain secrets or information that should in most case not be world-readable. You should remove all 'others' permissions with 'chmod o-rwx', and setup appropriate, exclusive permissions to the appropriate owner/group with chmod/chown."
|
||||
fi
|
||||
|
||||
return $ret
|
||||
}
|
||||
|
||||
|
|
Loading…
Add table
Reference in a new issue