• anarcat's avatar
    do not follow symlinks · 2a1c3e8c
    anarcat authored
    this is to avoid the possibility of Denial of Service attacks from the drupal admins: if someone were to create a symlink in files/ that would point to the parent sites/ directory, the recursive chmod that happen on verify would loop inifinitely (i saw one running for 1h)
    2a1c3e8c
provision.path.inc 12.7 KB