summaryrefslogtreecommitdiff
path: root/uploaded/server/php/files/.htaccess
diff options
context:
space:
mode:
authorHorus32014-12-01 02:09:10 +0100
committerHorus32014-12-01 02:09:10 +0100
commitb435ec462e0f39457e14d81750f07781db97cb91 (patch)
tree6923f685c0ca9d6fef80d3496c02e12318e68fdc /uploaded/server/php/files/.htaccess
parent33affa31742f0bc9d735349763f639087ea4e7ff (diff)
downloadtools.iamfabulous.de-b435ec462e0f39457e14d81750f07781db97cb91.tar.gz
File Uploaded added
Diffstat (limited to 'uploaded/server/php/files/.htaccess')
-rw-r--r--uploaded/server/php/files/.htaccess18
1 files changed, 18 insertions, 0 deletions
diff --git a/uploaded/server/php/files/.htaccess b/uploaded/server/php/files/.htaccess
new file mode 100644
index 0000000..56689f0
--- /dev/null
+++ b/uploaded/server/php/files/.htaccess
@@ -0,0 +1,18 @@
+# The following directives force the content-type application/octet-stream
+# and force browsers to display a download dialog for non-image files.
+# This prevents the execution of script files in the context of the website:
+ForceType application/octet-stream
+Header set Content-Disposition attachment
+<FilesMatch "(?i)\.(gif|jpe?g|png)$">
+ ForceType none
+ Header unset Content-Disposition
+</FilesMatch>
+
+# The following directive prevents browsers from MIME-sniffing the content-type.
+# This is an important complement to the ForceType directive above:
+Header set X-Content-Type-Options nosniff
+
+# Uncomment the following lines to prevent unauthorized download of files:
+#AuthName "Authorization required"
+#AuthType Basic
+#require valid-user