Browse Source

Deny access to composer.phar in .htaccess

This file might be present if users strictly follow our install instructions
 and don't delete it on their own after successfully installing Pico.
Daniel Rudolf 7 years ago
parent
commit
6bb65fb12b
1 changed files with 1 additions and 1 deletions
  1. 1 1
      .htaccess

+ 1 - 1
.htaccess

@@ -5,7 +5,7 @@
 
     # Deny access to internal dirs and files by passing the URL to Pico
     RewriteRule ^(config|content|content-sample|lib|vendor)(/|$) index.php [L]
-    RewriteRule ^(CHANGELOG\.md|composer\.(json|lock))(/|$) index.php [L]
+    RewriteRule ^(CHANGELOG\.md|composer\.(json|lock|phar))(/|$) index.php [L]
     RewriteRule (^\.|/\.)(?!well-known(/|$)) index.php [L]
 
     # Enable URL rewriting