Summary:
tmp/ and assets/ folders should not contains private and public files
Detailed Description:
By default, 'assets' and 'tmp' folders contain public and internal files.
(i know it's easy to modify with config.php file.)
but could it be possible to modify some defaults directories for next version
in /lib/classes/class.cms_config.php
in order to have Something like this for example:
$config['tmp_cache_location'] = $config['root_path'].'/tmp_secure/cache_cms';
$config['tmp_templates_c_location'] =
$config['root_path'].'/tmp_secure/cache_smarty';
$config['assets_dir'] = $config['root_path'].'/assets_secure'; (and move all
actual 'assets/' subfolders in it)
assets_secure/admin_custom
assets_secure/configs
assets_secure/module_custom
assets_secure/plugins
assets_secure/templates
tmp_secure/ (for log files)
tmp_secure/cache_cms (tmp_cache_location)
tmp_secure/cache_smarty ( tmp_templates_c_location)
folders that should Always be private !
and let users manage public files in:
assets/ ( for public static files : css js fonts etc …)
assets/css/
assets/js/
assets/fonts/
tmp/ (for public files generated by the CMS like stylesheets, captcha etc)
I know that this will cause some modules to crash !
(those who still use the path as a string 'tmp/' instead of using constants and
$config var.)
in my opinion :
1.overall improvement, by forcing all module creators to comply permanently to
use the correct directory references in their scripts!
2.Better management of files between public and private.
3.much easier to secure with chmod and faster process on htaccess