Skip to content

Conversation

@Uzlopak
Copy link
Contributor

@Uzlopak Uzlopak commented Oct 15, 2025

If serve is set to false, it only allows to send files specified with an absolute path. Or else sendFile makes no sense anymore, despite that we want to allow the use of sendFile.

Checklist

Copy link
Contributor

@ilteoood ilteoood left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Uzlopak
Copy link
Contributor Author

Uzlopak commented Oct 15, 2025

I would like to have a review by @climba03003 or @is2ei regarding the security aspect.

@is2ei
Copy link
Contributor

is2ei commented Oct 16, 2025

I think @climba03003 would be the right person, as he originally mentioned the security concern.

@Uzlopak
Copy link
Contributor Author

Uzlopak commented Oct 16, 2025

I pinged him on discord. Lets see if he has time.

Copy link
Member

@climba03003 climba03003 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@Uzlopak Uzlopak linked an issue Oct 16, 2025 that may be closed by this pull request
2 tasks
If serve is set explicitly to false then root is required If root is set, it must be validated
@Uzlopak
Copy link
Contributor Author

Uzlopak commented Oct 16, 2025

@is2ei
Can you have a review regarding the root option check?

Copy link
Contributor

@is2ei is2ei left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@Uzlopak Uzlopak merged commit 27f2bfe into main Oct 16, 2025
17 checks passed
@Uzlopak Uzlopak deleted the no-mandatory-root branch October 16, 2025 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

5 participants