Skip to content

Avoid world readable config.db #242

@thomasbach-dev

Description

@thomasbach-dev

Hi there,

thanks a lot for this piece of software. I have not really come to use it yet, but it looks excellent.

While setting up a headless sync server I noticed that config.db is initially in mode 0644. This could be a security risk as this file contains credentials remote_access_username and remote_access_password. Please make this file accessible only by the user executing mnemosyne.

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions