Files
myron bb21fca399 Security: block direct upload access, fix view-doc path traversal guard
- uploads/.htaccess: deny all direct web access to uploaded customer docs
- admin/view-doc.php: add realpath() path-traversal check (mirrors view-doc.php)
- admin/view-doc.php: remove dead double-query (result was always overwritten)
- .gitignore: uploads/* wildcard so .htaccess can be tracked
2026-06-13 14:20:41 +00:00

7 lines
52 B
Plaintext

*.log
.DS_Store
*.swp
uploads/*
!uploads/.htaccess