From 1a0284164936ab4984f9c52fd3ba8c9b25e81959 Mon Sep 17 00:00:00 2001 From: Shannon Date: Tue, 28 Jun 2016 16:01:23 +0200 Subject: [PATCH 1/2] U4-8472 Add web.config file to media folder path to prevent all execution based files from being run by IIS --- src/Umbraco.Web.UI/Media/Web.config | 9 +++++++++ src/Umbraco.Web.UI/Umbraco.Web.UI.csproj | 6 +++--- 2 files changed, 12 insertions(+), 3 deletions(-) create mode 100644 src/Umbraco.Web.UI/Media/Web.config diff --git a/src/Umbraco.Web.UI/Media/Web.config b/src/Umbraco.Web.UI/Media/Web.config new file mode 100644 index 0000000000..6cbb733ea7 --- /dev/null +++ b/src/Umbraco.Web.UI/Media/Web.config @@ -0,0 +1,9 @@ + + + + + + + + + \ No newline at end of file diff --git a/src/Umbraco.Web.UI/Umbraco.Web.UI.csproj b/src/Umbraco.Web.UI/Umbraco.Web.UI.csproj index 6911829bb8..0243fbbf0c 100644 --- a/src/Umbraco.Web.UI/Umbraco.Web.UI.csproj +++ b/src/Umbraco.Web.UI/Umbraco.Web.UI.csproj @@ -695,6 +695,7 @@ Designer + Designer @@ -2383,7 +2384,6 @@ - @@ -2441,8 +2441,8 @@ xcopy "$(ProjectDir)"..\packages\SqlServerCE.4.0.0.1\x86\*.* "$(TargetDir)x86\" - - + + From 0f19937aec3ebbaf4193b322d4934687d69e8b34 Mon Sep 17 00:00:00 2001 From: Sebastiaan Janssen Date: Wed, 6 Jul 2016 12:31:44 +0200 Subject: [PATCH 2/2] Making sure the media/web.config is correctly installed from nuget --- build/NuSpecs/UmbracoCms.nuspec | 1 + 1 file changed, 1 insertion(+) diff --git a/build/NuSpecs/UmbracoCms.nuspec b/build/NuSpecs/UmbracoCms.nuspec index 66e82ac488..5ee38e57fe 100644 --- a/build/NuSpecs/UmbracoCms.nuspec +++ b/build/NuSpecs/UmbracoCms.nuspec @@ -32,6 +32,7 @@ +