Try to explain editor loophole to viewing restrictions

master
https://social.mayfirst.org/mjray 2018-02-05 06:51:48 -04:00 committed by admin
parent c4042853b3
commit 36bb1f6dc7
1 changed files with 4 additions and 0 deletions

View File

@ -40,3 +40,7 @@ much more maintainable htaccess file.
>>>>> If you use the httpauth and the cgiauthurl method, you can restrict a path
>>>>> like /private/* to be accessible only under the authenticated request uri.
>>>>>> Note that if editing is enabled, then you should set the restriction in locked_pages too
>>>>>> or they may be able to view pages by editing the page= value in the editor's
>>>>>> query string. --[mjr](http://mjr.towers.org.uk/)