From dde67de0f656014821942ee8abe50f5187924288 Mon Sep 17 00:00:00 2001 From: Rik <gitaarik@gmail.com> Date: Sat, 22 Feb 2014 13:07:50 +0100 Subject: [PATCH] [1.6.x] Fixed #12670 -- Added a note about permissions of files stored in FILE_UPLOAD_TEMP_DIR. Thanks simon29 for the suggestion. Backport of 355572ac56 from master --- docs/topics/http/file-uploads.txt | 3 +++ 1 file changed, 3 insertions(+) diff --git a/docs/topics/http/file-uploads.txt b/docs/topics/http/file-uploads.txt index 211ffa1e5a..58e16be42c 100644 --- a/docs/topics/http/file-uploads.txt +++ b/docs/topics/http/file-uploads.txt @@ -164,6 +164,9 @@ Three settings control Django's file upload behavior: of ``0600``, and files saved from memory will be saved using the system's standard umask. + For security reasons, these permissions aren't applied to the temporary + files that are stored in :setting:`FILE_UPLOAD_TEMP_DIR`. + .. warning:: If you're not familiar with file modes, please note that the leading