busybox11 / NowPlaying-for-Spotify

A Spotify Connect visualizer
https://nowplayi.ng
GNU General Public License v3.0
185 stars 23 forks source link

Patch .env security hole #69

Closed JohnB17 closed 3 years ago

JohnB17 commented 3 years ago

68 and #67 added a .env but in its current state you can go to https://yoursite.com/.env and it would download the .env to its fullest. This pull request redirects /.env to the error 403 page, but since Nginx doesn't support .htaccess, I added to the readme on instructions for Nginx. I also updated the readme to change the instructions on how to add Spotify id and secret since they still said the PHP files.

finnie2006 commented 3 years ago

Thx for making the pr

busybox11 commented 3 years ago

Thanks a lot for your PR!