Skip to content

Place vendor folder in the trustpath #1682

@fiammybe

Description

@fiammybe

This is security hardening : the vendor folder should not be publicly accessible. Initialy mentioned by @MekDrop here : #1677 (comment)
The problem is that the trustpath is not yet known at the moment of installation, and the installation program needs a working composer.
This will need some more experimenting with the installer.

The current Composer branch already supports moving the vendor folder (there is a directive in the composer file for that). The tricky part is to get the installer working with it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions