Table of Contents Previous Section

Securing Application Source Code

Clients can browse source code in DOCUMENT_ROOT/WebObjects unless you take steps to prevent them. If you don't deny access, a user could submit this URL:

    http://host/WebObjects

They could get a directory listing of WebObjects applications on your machine and, from there, browse the source code of scripted and compiled applications.

You can take two approaches to prevent this breach of security: