rspec/rules/S5691/ask-yourself.adoc
2021-01-27 13:42:22 +01:00

7 lines
377 B
Plaintext

== Ask Yourself Whether
* Hidden files may have been inadvertently uploaded to the static server's public directory and it accepts requests to hidden files.
* There is no business use cases linked to serve files in ``++.name++`` format but the server is not configured to reject requests to this type of files.
There is a risk if you answered yes to any of those questions.