YunoHost-Apps / ampache_ynh

Ampache package for YunoHost
http://ampache.org/
GNU General Public License v3.0
17 stars 16 forks source link

[SECURITY] Database password and secret key are readable by all users #77

Closed Jules-Bertholet closed 3 years ago

Jules-Bertholet commented 3 years ago

The password to the Ampache database, and the Ampache secret_key, are stored in $final_path/config/ampache.cfg.php, which all users can read.