RE: Using symlinks in webapps

2003-06-04 Thread Denise Mangano
Ok sorry for that. Finally got the right answer from the archives. Apparently symlinks have been disabled since 4.1.12 for security reasons. I noticed in the archives that it was suggested to set the allowLinking in my server.xml file be enough? Resources

Re: Using symlinks in webapps

2003-06-04 Thread Bill Barker
The security risk are relatively minor if you have control over who can update your webapp. An example of a problem (if you aren't using a sandbox) would be somebody deciding to do ln -s /etc/passwd within $CATALINA_HOME/webapps/ROOT (and letting the entire world know what user accounts are on