this doesn't seem the right way to prevent the cross-dir problem. Postponed
Massimo Melina committed
Dec 14, 2021 at 16:23 UTC
b62e9f1388178cd17aece8dea748462eaa5ec0ba
5 files changed
+27
-31
NOTES.md
deleted
-25
@@ -1,25 +0,0 @@
1
-# File browser
2
-- Consider packing toolkit
3
- - if it's a "no", download CDN stuff
4
-
5
-## What GUI lib?
6
-
7
-### Material
8
-- css+js
9
- - https://materializecss.com/
10
-- preact wrapper for [MCW](https://github.com/material-components/material-components-web)
11
- - https://github.com/developit/preact-material-components
12
-
13
-### Others
14
-- https://preactjs.com/about/libraries-addons/
15
- - [fluid](https://unpkg.com/preact-fluid@0.9.1/lib/index.js)
16
- - no module?
17
-
18
-# Study
19
-https://www.tutorialspoint.com/koajs/koajs_quick_guide.htm
20
-
21
-# To do
22
-- vfs
23
- - yaml
24
-- sticky breadcrumbs
25
-- interruption of long requests if client aborted
\ No newline at end of file
dev-notes.md
new
+24
@@ -0,0 +1,24 @@
1
+# What GUI lib?
2
+- none?
3
+ - would none allow easier customization?
4
+- material
5
+ - css+js https://materializecss.com/
6
+
7
+# Study
8
+- https://www.tutorialspoint.com/koajs/koajs_quick_guide.htm
9
+
10
+# To do
11
+- fix dist
12
+- vfs: rename file in source folder
13
+- vfs: hide file in source folder
14
+- fix: crash if vfs is not loadable
15
+- vfs: serve an html for a folder?
16
+ - "default" property for vfsNode?
17
+- sticky breadcrumbs
18
+- interruption of long requests if client aborted
19
+- frontend
20
+ - don't depend on cdn
21
+- webdav?
22
+- streamable zip archives
23
+ - no compression
24
+ - resumable?
\ No newline at end of file
src/apis.ts
+1
-1
@@ -12,7 +12,7 @@ type ApiHandlers = Record<string, ApiHandler>
12
export function apiMw(apis: ApiHandlers) : Koa.Middleware {
13
return async (ctx, next) => {
14
const params = ctx.request.body
15
- console.log('API', ctx.method, ctx.path, params)
15
+ console.debug('API', ctx.method, ctx.path, params)
16
// @ts-ignore
17
ctx.assert(ctx.path in apis, 404, 'invalid api')
18
const cb = (apis as any)[ctx.path]
src/index.ts
+1
-4
@@ -11,10 +11,7 @@ const PORT = 80
11
const srv = new Koa()
12
srv.use(async (ctx, next) => {
13
// log all requests
14
- console.debug(ctx.request.method, ctx.url)
15
- // prevent cross-dir
16
- // @ts-ignore
17
- ctx.assert(!ctx.originalUrl.includes('..'), 400, 'cross-dir')
14
+ console.debug(new Date().toLocaleTimeString(), ctx.request.method, ctx.url)
15
await next()
16
})
17
tests/test.ts
+1
-1
@@ -1,7 +1,7 @@
1
const axios = require('axios')
2
3
describe('file', () => {
4
- itHttp('md', '/NOTES.md', '##')
4
+ itHttp('md', '/dev-notes.md', '#')
5
itHttp('frontend', '/', '<body>')
6
itHttp('api.list', '/~/api/file_list', data => Array.isArray(data.list))
7
})