Aren't we supposed to do something to secure the config.inc.php file? Like something in .htaccess or moving it out of the includes directory or tightening permissions? It seemed there used to be two or three recommended steps, but now it seems like we just leave it in includes with the same 0666 permissions as the rest of the includes directory files, according to the installation documentation. Is that right? Is it secure? Doesn't it leave the database user and that user's password open for reading?
Thanks in advance,
Maria