Why are handlers cleared in Web.config?

Topics: Core
Aug 21, 2012 at 12:17 PM

I see that in Orchard's Web.config in the handlers sections first all handlers are cleared. What exactly is the purpose of this? What handlers probably existing are problematic?

Thanks in advance.

Aug 22, 2012 at 2:22 AM

Security. It's all about reducing the attack surface to what you really need.

Aug 22, 2012 at 10:33 AM

OK, thanks.