Come together with the global Drupal community in Rotterdam, 28 Sept – 1 Oct 2026. Sessions, contribution, connection, and Early Bird savings until 8 June.
It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead.
Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.
As this is such a simple change, and has already been committed to D8 (where there's very little difference in the patch), I am going to take that as an RTBC.
Comments
Comment #2
mcdruid commentedComment #3
mcdruid commentedComment #4
mcdruid commentedComment #5
ayesh commentedLoos good to me.
Comment #6
mcdruid commentedThanks Ayesh!
As this is such a simple change, and has already been committed to D8 (where there's very little difference in the patch), I am going to take that as an RTBC.
Comment #7
gregglesAgreed on RTBC. Tests pass, the change is the same as D8 https://git.drupalcode.org/project/drupal/commit/fd194bb
Comment #8
joseph.olstadComment #9
joseph.olstadComment #10
mcdruid commentedn.b. we need to update issue credit here based on the D8 parent when this is committed.
Comment #11
fabianx commentedRTBM - please commit when ready
Comment #19
mcdruid commentedAdding issue credit from the D8 parent #2820611: FileStorage generated .htaccess doesn't cover PHP 7.
Comment #21
mcdruid commentedThank you everyone that contributed!