Title:
Either remove allowedextforinclude functionality entirely, or at least implement it so it can be disabled
| View in TrackerStatus/Resolution/Reason: Closed/Fixed/
Reporter/Name(from Bugbase): Adam Cameron / Adam Cameron (Adam Cameron)
Created: 02/19/2014
Components: General Server
Versions: 11.0
Failure Type:
Found In Build/Fixed In Build: PublicBeta /
Priority/Frequency: Major / All users will encounter
Locale/System: English / Platforms All
Vote Count: 3
See: http://cfmlblog.adamcameron.me/2014/02/coldfusion-11-preventing-files-from.html
This functionality ought to just be removed, because it's ill-conceived.
However if it needs to remain in the product, then some tweaks are needed:
* disable it by default
* add wildcard support for the setting
* add a UI for it into CFAdmin
But, seriously, save everyone some time and just get rid.
--
Adam
----------------------------- Additional Watson Details -----------------------------
Watson Bug ID: 3710326
External Customer Info:
External Company:
External Customer Name: Adam Cameron.
External Customer Email:
External Test Config: My Hardware and Environment details:
Attachments:
Comments: