> >>
> >> So you want roadblocks.  You want the dancer helper app to generate an
> app that won’t run at all until you go in and hack on some configuration
> files.  Do I have that right?
> >
> > No, you don't.  Read it again?
> Yes, I know what it says.  I also know what he asked for originally, and
> what the title of this thread is.
> I don’t see how it makes Dancer more secure to point users to the docs
> from a configuration file when those docs are already present.  The only
> way a configuration file change can make Dancer more secure is to either
> bind to localhost, or turn off the listener entirely, in order to force
> users to RTFM before they can get a new Dancer app to do what they almost
> certainly actually want.
> Regardless, the claim that Dancer is “insecure” by default has yet to be
> demonstrated.  Show me an attack on a default Dancer app, and we can talk
> about it.  Simply pointing out that it listens on a public IP is not a
> demonstration of insecurity.
The title of this message probably should have been a question or phrased
in some other way, but the suggestion to have commented out configuration
options? How would these entries in the configuration file constitute a

# Enable the following line to limit the server to only listen to localhost:
# server: ""

# Enable the following line to turn on file-based session management:
# session: "YAML"

