Skip to content

Conversation

@amulet1
Copy link

@amulet1 amulet1 commented Jun 25, 2025

Could we drop the unrestricted access directives and instead rely on the web server global configuration?

At best it is not needed, and at worst it is a security concern as it overrides a potentially more restrictive web server configuration.

The "allow all" is at best not needed, and at worst it overrides a potentially more restrictive web server configuration.
@TDannhauer
Copy link

Fine for me.

Any concerns @ralflang ?

@ralflang
Copy link
Member

ralflang commented Aug 7, 2025

I'd rather keep it until dynamic configuration is ready. Let's finish the stable release todos first. Afterwards we should drop the file altogether and let the config tool write it (if needed).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants