Although the Drupal site goes into great detail about permissions and security, there are only vague/unclear references to shared hosting. From a Drupal point of view, what is the most secure set-up (ownership and permission levels) for a site on shared hosting?
As an example of the kind of info I’m looking for, WordPress suggests the following shared hosting settings:
- All files should be owned by the actual user’s account, not the user account used for the httpd process.
- Group ownership is irrelevant, unless there’s specific group requirements for the web-server process permissions checking. This is not usually the case.
- All directories should be 755 or 750.
- All files should be 644 or 640. Exception: wp-config.php should be 600 to prevent other users on the server from reading it.
- No directories should ever be given 777, even upload directories. Since the php process is running as the owner of the files, it gets the owners permissions and can write to even a 755 directory.
Sponsored by SupremePR