سؤال

Is it safe to store .properties in WEB-INF/classes? Can anybody see its content via browser?

هل كانت مفيدة؟

المحلول

WEB-INF is not directly accessible from a browser, so most normal browser activity should not find it.

However, if the server does not restrict navigation by .. (parent of), many things on the server may become visible that were never meant to be. (Yes, that is improper implementation, but humans are involved.)

مرخصة بموجب: CC-BY-SA مع الإسناد
لا تنتمي إلى StackOverflow
scroll top