A rookie question here: Is it normal I can access all of my directories and files through the web browser? Isn't this risky and insecure? How can I change it?
I thought only www/var/ directory could be accessed through the browser.
A rookie question here: Is it normal I can access all of my directories and files through the web browser? Isn't this risky and insecure? How can I change it?
I thought only www/var/ directory could be accessed through the browser.
This behavior is normal and safe.
You are acessing your file system through the browser, as is the default behavior for browsers. You could do the same even if there were no server available on your machine.
In the same way, accessing a web address through most file explorers will also work.
What you experience is access that is not passign through the http server, and an outside user (not in your machine) will not be able to access your file system.
FYI, most http servers do have an option to allow listing of files, witch is disabled by default.