mirror of
https://github.com/myronblair/epictravelexpeditions
synced 2026-07-28 08:52:26 -05:00
Fix security gaps and dead code found in codebase review
- mailer.php: re-enable TLS certificate verification for CyberMail API calls (was CURLOPT_SSL_VERIFYPEER => false, exposing outbound mail traffic to MITM). - .htaccess / api/.htaccess: block direct HTTP access to .git/, db/, and api/config.php via mod_rewrite [F] rules. Confirmed live that /.git/config, /.git/logs/HEAD, and /db/schema.sql were all directly downloadable (200 OK with real content) - .git exposure leaks the repo's embedded GitHub token and full history; schema.sql leaks the DB layout. Also drops the dead "/setup -> setup_password.php" rewrite, since that file was already deleted from production. - index.php: remove the 'download' route, which required a api/download.php that has never existed in this repo - confirmed live that GET /api/download returns a fatal 500. - functions.php / upload.php / testimonials.php: extract the duplicated image-upload validation/move logic (MIME check, size check, UUID rename, move_uploaded_file) into one handleImageUpload() helper used by both upload endpoints. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+6
-1
@@ -4,7 +4,12 @@
|
||||
<IfModule mod_rewrite.c>
|
||||
RewriteEngine On
|
||||
RewriteBase /api/
|
||||
|
||||
|
||||
# Block direct access to config.php / .env - this was reachable at
|
||||
# /api/config.php in production (200 OK) despite the FilesMatch/Require
|
||||
# rule below, which LiteSpeed appears not to honor from .htaccess here.
|
||||
RewriteRule ^(config\.php|\.env)$ - [F,L]
|
||||
|
||||
# Route all requests to index.php
|
||||
RewriteCond %{REQUEST_FILENAME} !-f
|
||||
RewriteCond %{REQUEST_FILENAME} !-d
|
||||
|
||||
Reference in New Issue
Block a user