From 997ffe08eb8056bebb5481b14ed1da77b9adab2c Mon Sep 17 00:00:00 2001 From: "AVE.cms" Date: Thu, 30 Jul 2026 11:57:36 +0300 Subject: [PATCH] Restore runtime directory guards --- tmp/.htaccess | 1 + uploads/.htaccess | 33 +++++++++++++++++++++++++++++++++ uploads/index.php | 21 +++++++++++++++++++++ 3 files changed, 55 insertions(+) create mode 100644 tmp/.htaccess create mode 100644 uploads/.htaccess create mode 100644 uploads/index.php diff --git a/tmp/.htaccess b/tmp/.htaccess new file mode 100644 index 0000000..14249c5 --- /dev/null +++ b/tmp/.htaccess @@ -0,0 +1 @@ +Deny from all \ No newline at end of file diff --git a/uploads/.htaccess b/uploads/.htaccess new file mode 100644 index 0000000..644767d --- /dev/null +++ b/uploads/.htaccess @@ -0,0 +1,33 @@ +# Files in uploads are public static assets and must never be executable. +Options -Indexes -ExecCGI + + + RemoveHandler .php .php3 .php4 .php5 .php7 .php8 .phtml .phar .cgi .pl .py .rb .sh + RemoveType .php .php3 .php4 .php5 .php7 .php8 .phtml .phar .cgi .pl .py .rb .sh + + + + + Require all denied + + + Order allow,deny + Deny from all + + + + + + Header set Content-Security-Policy "sandbox; default-src 'none'; style-src 'unsafe-inline'" + Header set Content-Disposition "attachment" + Header set X-Content-Type-Options "nosniff" + + + +#Header set Cache-Control "max-age=7200, must-revalidate" + + + RewriteEngine On + RewriteCond %{REQUEST_FILENAME} !-f + RewriteRule .(jpg|JPG|jpeg|JPEG|gif|GIF|png|PNG|webp|WEBP|bmp|BMP) /inc/thumb.php [QSA,L] + diff --git a/uploads/index.php b/uploads/index.php new file mode 100644 index 0000000..9aa3ce5 --- /dev/null +++ b/uploads/index.php @@ -0,0 +1,21 @@ + + | @copyright 2007-2026 (c) AVE.cms + | @link https://ave-cms.ru + | @version 3.3 + */ + + /** + * Файл-заглушка, предназначенный для запрета показа списка файлов в текущей директории, + * если через адресную строку браузера было прямое общращение к данной директории. + */ + header('Location:/'); + exit; + ?>