Status Report error "Public files directory | Not fully protected" links to page with no D8 information

Created on 29 October 2018, over 6 years ago
Updated 17 April 2025, 30 days ago

If you are running Drupal version 8.6.2, and Drupal detects something wrong with your .htaccess file in your public files/ directory, it gives this error in Reports > Status Report:

Public files directory
Not fully protected
See https://www.drupal.org/SA-CORE-2013-003 β†’ for information about the recommended .htaccess file which should be added to the /.../files directory to help protect against arbitrary code execution.

However, the page linked to, https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-... β†’ , lists this security notice as applying to Drupal versions 6.x and 7.x, and contains no information specifically indicated as instructions for version 8.x.

This is ambiguous and confusing.

πŸ› Bug report
Status

Active

Version

11.0 πŸ”₯

Component

documentation

Created by

πŸ‡ΊπŸ‡ΈUnited States slefevre@ccad.edu

Live updates comments and jobs are added and updated live.
  • Documentation

    Primarily changes documentation, not code. For Drupal core issues, select the Documentation component instead of using this tag. In general, component selection is preferred over tag selection.

  • Novice

    It would make a good project for someone who is new to the Drupal contribution process. It's preferred over Newbie.

  • Needs issue summary update

    Issue summaries save everyone time if they are kept up-to-date. See Update issue summary task instructions.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024