You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Feb 25, 2022. It is now read-only.
I think that the 403 from static is accurate, if inconvenient and scary to the visitor. But come on, what should a visitor expect that is trying to sniff around in our .env files? Originally posted by @trieloff in #218 (comment)
i just realized that apple pay requires access to a .well-known folder for domain verification.
i am not sure what would be the best way forward on this, any ideas? this may or may not be the only place where this happens, so i wonder if we should revisit the blacklisting of all . folder and be more selective or if we should white-list things selectively over the . blacklist.
The text was updated successfully, but these errors were encountered:
davidnuescheler
changed the title
justified usecase: for access with files in a folder starting with a dot
justified usecase for access with files in a folder starting with a dot
Apr 20, 2020
i just realized that apple pay requires access to a
.well-known
folder for domain verification.https://developer.apple.com/documentation/apple_pay_on_the_web/maintaining_your_environment#3179140
i am not sure what would be the best way forward on this, any ideas? this may or may not be the only place where this happens, so i wonder if we should revisit the blacklisting of all
.
folder and be more selective or if we should white-list things selectively over the.
blacklist.The text was updated successfully, but these errors were encountered: