Security & /static/files....
Hello,
I use Antclick 1.0.1 and noticed that you can access the folder listings of files and images by simple typing www.asdfasdf.com/static/files/nameofweblog. This even works when the weblog is private, not public!
Has this been fixed in 1.0.2? (Unfortunately, Helma does not start on 2 server I tested 1.0.2 on, 1.0.1 works fine). As a "workaround", I am going to insert a blank index.html in these folders.
I also thought of Apache rewrite rules, so that everyone who tries to access the static-folders directly gets redirected to the frontpage of each weblog.
Any infos appreciated! Thanks