The TUS PATCH handler copied the whole request body to disk and used the declared Upload-Length only to decide when the upload was complete. A client could declare a tiny Upload-Length and then stream an arbitrarily large body in a single PATCH, writing it all to disk, so any user with create permission could exhaust the filesystem. Bound each write to the bytes still expected (Upload-Length - Upload-Offset), reject a PATCH whose offset already exceeds the declared length, and roll back and reject a body that exceeds it. This complements the existing negative Upload-Length handling. Refs GHSA-ffv3-7h97-993q |
||
|---|---|---|
| .github | ||
| auth | ||
| branding | ||
| cmd | ||
| diskcache | ||
| docker | ||
| errors | ||
| files | ||
| fileutils | ||
| frontend | ||
| http | ||
| img | ||
| rules | ||
| runner | ||
| search | ||
| settings | ||
| share | ||
| storage | ||
| users | ||
| version | ||
| www | ||
| .dockerignore | ||
| .gitignore | ||
| .golangci.yml | ||
| .goreleaser.yml | ||
| .versionrc | ||
| CHANGELOG.md | ||
| CODE-OF-CONDUCT.md | ||
| compose.yaml | ||
| CONTRIBUTING.md | ||
| Dockerfile | ||
| Dockerfile.s6 | ||
| go.mod | ||
| go.sum | ||
| LICENSE | ||
| main.go | ||
| README.md | ||
| renovate.json | ||
| SECURITY.md | ||
| Taskfile.yml | ||
| transifex.yml | ||
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview and edit your files. It is a create-your-own-cloud-kind of software where you can just install it on your server, direct it to a path and access your files through a nice web interface.
Documentation
Documentation on how to install, configure, and contribute to this project is hosted at filebrowser.org.
Project Status
This project is a finished product which fulfills its goal: be a single binary web File Browser which can be run by anyone anywhere. That means that File Browser is currently on maintenance-only mode. Therefore, please note the following:
- It can take a while until someone gets back to you. Please be patient.
- Issues are meant to track bugs. Unrelated issues will be converted into discussions.
- The priority is triaging issues, addressing security issues and reviewing pull requests meant to solve bugs.
- No new features are planned. Pull requests for new features will not be reviewed.
Please read @hacdias' personal reflection on the project status.
Contributing
Contributions are always welcome. To start contributing to this project, read our guidelines first.
License
Apache License 2.0 © File Browser Contributors