By poker10 on
Change record status:
Published (View all published change records)
Project:
Introduced in branch:
7.x
Introduced in version:
7.103
Issue links:
Description:
The previous behavior for displaying errors in Drupal 7 was to display full path of the affected file (including DRUPAL_ROOT path). This has security implications.
Original error message example:
Warning: file_get_contents(/x.txt): Failed to open stream: No such file or directory in include_once() (line 312 of /var/www/test/sites/default/settings.php).
After this change, all displayed errors have now the DRUPAL_ROOT path stripped from the full path. Only the relative path to the Drupal root directory will be displayed.
New error message example:
Warning: file_get_contents(/x.txt): Failed to open stream: No such file or directory in include_once() (line 312 of sites/default/settings.php).
Impacts:
Site builders, administrators, editors
Module developers
Site templates, recipes and distribution developers