- Issue created by @tsotoodeh
- Status changed to Closed: works as designed
almost 2 years ago 3:24pm 5 February 2023 - 🇮🇷Iran tsotoodeh
Just remove the commas and you'll be fine
That's right!
Does not happen to came across a extension definition which accepts space as a separator!
Regarding the security concern of defining * as the accepted format for Drupal user1, what are the justification from the security perspective behind this decision? Could you evaluate on this matter? Thank you. "administer imce" permission is flagged as "restrict access" so it should be granted to trusted users only. Even if you have the permission to upload all extensions you'll still need to enable
allow_insecure_uploads
config option manually in order to upload insecure extensions likephp js
- 🇮🇷Iran tsotoodeh
That's good answer. By all means it would be good to warn the user1 holder to configure and customize the Admin profile extensions by the time module is installed properly. That would make Drupal aspect, secure as designed in every step of its life cycle. Keep the good work.