OpenConext / Stepup-tiqr

tiqr IdP for step-up authentication
Apache License 2.0
3 stars 2 forks source link

Remove .htaccess file #53

Closed MKodde closed 6 years ago

MKodde commented 6 years ago

Even though the .htaccess file is not used, (it was added from the skeleton Symfony installation) users where able to download it. This was reported in a security audit.

The most pragmatic fix is to remove this obsolete file.

pablothedude commented 6 years ago

Travis is failing? https://www.pivotaltracker.com/story/show/158356638/comments/193850868

MKodde commented 6 years ago

Yes @pablothedude , this is fixed in #54 These two branches should not conflict. So merge as you see fit!