Database migration should ensure stash-config.properties file permission is 0640

XMLWordPrintable

      The stash-config.properties contains sensitive information like SQL credentials in plain text. The contents of the file should not be world-readable.

      Stash uses the default file permissions of the running user for all the files it creates. For a zip/tar.gz install of Stash it is up to the administrator to configure the run user correctly. However, the Linux installer automatically creates atlstash user. The installer should ensure the stash-config.properties file is not world-readable.

            Assignee:
            rikf
            Reporter:
            Andrew Er (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: