1.2 Set permissions on local-settings.js

Information

Set permissions on local-settings.js so that it can only be modified or deleted by an Administrator.
Any users with the ability to modify the local-settings.js file can bypass all security configurations by changing the file or deleting it.

Solution

Deny non-administrators the ability to write to local-settings.js.

See Also

https://workbench.cisecurity.org/files/1158