diff --git a/Documentation.html b/Documentation.html index 20c2c03bc9..158526009d 100644 --- a/Documentation.html +++ b/Documentation.html @@ -312,7 +312,7 @@ rm -rf config # remove not needed directory authentication mode.
  • You should deny access to the ./libraries and ./setup/lib subfolders in your webserver configuration. For - Apache you can use supplied .htaccess file in that folder, for other + Apache you can use supplied .htaccess file in that folder, for other webservers, you should configure this yourself. Such configuration prevents from possible path exposure and cross side scripting vulnerabilities that might happen to be found in that code.
  • @@ -480,7 +480,7 @@ GRANT ALL PRIVILEGES ON user_base.* TO 'real_user'@localhost IDENTIFIED BY 'real 1.35.
  • See also FAQ 4.4 about not - using the .htaccess mechanism along with + using the .htaccess mechanism along with 'HTTP' authentication mode.
  • @@ -538,7 +538,7 @@ GRANT ALL PRIVILEGES ON user_base.* TO 'real_user'@localhost IDENTIFIED BY 'real
  • Unlike cookie and http, does not require a user to log in when first loading the phpMyAdmin site. This is by design but could allow any user to access your installation. Use of some restriction method is - suggested, perhaps a .htaccess file with the + suggested, perhaps a .htaccess file with the HTTP-AUTH directive or disallowing incoming HTTP requests at one’s router or firewall will suffice (both of which are beyond the scope of this manual but easily searchable with Google).
  • @@ -3061,7 +3061,7 @@ the order of the server paragraph in config.inc.php. Options FollowSymLinks and AllowOverride FileInfo enabled for directory where phpMyAdmin is installed and you need mod_rewrite to be enabled. Then you just need to create following - .htaccess file in root folder of phpMyAdmin installation + .htaccess file in root folder of phpMyAdmin installation (don't forget to change directory name inside of it):

    @@ -3613,7 +3613,7 @@ have either the APC extension
         This depends on your system.
    If you're running a server which cannot be accessed by other people, it's sufficient to use the directory protection bundled with your webserver - (with Apache you can use .htaccess files, for example).
    + (with Apache you can use .htaccess files, for example).
    If other people have telnet access to your server, you should use phpMyAdmin's HTTP or cookie authentication features.

    @@ -3657,7 +3657,7 @@ have either the APC extension are wrong.
  • The username/password you specify in the login dialog are invalid.
  • You have already setup a security mechanism for the - phpMyAdmin-directory, eg. a .htaccess file. This would interfere with + phpMyAdmin-directory, eg. a .htaccess file. This would interfere with phpMyAdmin's authentication, so remove it.
  • @@ -3673,7 +3673,7 @@ have either the APC extension

    4.6 How can I use the Host-based authentication additions?

    -

    If you have existing rules from an old .htaccess file, you can take them +

    If you have existing rules from an old .htaccess file, you can take them and add a username between the 'deny'/'allow' and 'from' strings. Using the username wildcard of '%' would be a major benefit here if your installation is suited to using it. Then