Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Moodle
  3. Moodle Security Check - File Permissions

Moodle Security Check - File Permissions

Scheduled Pinned Locked Moved Solved Moodle
3 Posts 3 Posters 4.0k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F Offline
    F Offline
    farmerjo
    wrote on last edited by
    #1

    Hi,
    Running the "Reports / Security Checks" on the Cloudron Moodle app shows the following:

    Error Check all public / private paths
    ^..* files should not be public
    composer.json files should not be public
    .lock files should not be public
    environment.xml files should not be public
    Directory index should not be enabled (Returned a 403, ideally should be 404)
    db/install.xml files should not be public
    readme.txt files should not be public
    README files should not be public
    /upgrade.txt files should not be public
    phpunit.xml files should not be public
    /fixtures/ files should not be public
    /behat/ files should not be public

    Could you please update the install script to address there?

    nebulonN 1 Reply Last reply
    1
    • F farmerjo

      Hi,
      Running the "Reports / Security Checks" on the Cloudron Moodle app shows the following:

      Error Check all public / private paths
      ^..* files should not be public
      composer.json files should not be public
      .lock files should not be public
      environment.xml files should not be public
      Directory index should not be enabled (Returned a 403, ideally should be 404)
      db/install.xml files should not be public
      readme.txt files should not be public
      README files should not be public
      /upgrade.txt files should not be public
      phpunit.xml files should not be public
      /fixtures/ files should not be public
      /behat/ files should not be public

      Could you please update the install script to address there?

      nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote on last edited by nebulon
      #2

      @farmerjo thanks for the heads up! For existing installations, add a file at /app/data/.htaccess with the following content:

      # https://docs.moodle.org/311/en/Apache#Installing_Apache
      
      AcceptPathInfo On
      
      ErrorDocument 404 /error/index.php
      
      # This sends any 403 from apache through to the same page, but also
      # overrides the http status with 404 instead for better security.
      ErrorDocument 403 /error/index.php?code=404
      
      RewriteEngine On
      
      RewriteRule "(\/vendor\/)" - [F]
      RewriteRule "(\/node_modules\/)" - [F]
      RewriteRule "(^|/)\.(?!well-known\/)" - [F]
      RewriteRule "(composer\.json)" - [F]
      RewriteRule "(\.lock)" - [F]
      RewriteRule "(\/environment.xml)" - [F]
      # Options -Indexes
      RewriteRule "(\/install.xml)" - [F]
      RewriteRule "(\/README)" - [F]
      RewriteRule "(\/readme)" - [F]
      RewriteRule "(\/moodle_readme)" - [F]
      RewriteRule "(\/upgrade\.txt)" - [F]
      RewriteRule "(phpunit\.xml\.dist)" - [F]
      RewriteRule "(\/tests\/behat\/)" - [F]
      RewriteRule "(\/fixtures\/)" - [F]
      

      We wil provide a new package which will have that by default.

      1 Reply Last reply
      3
      • girishG Do not disturb
        girishG Do not disturb
        girish
        Staff
        wrote on last edited by
        #3

        I have pushed a new package.

        1 Reply Last reply
        2

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search