this doesn't seem the right way to prevent the cross-dir problem. Postponed

Massimo Melina committed Dec 14, 2021 at 16:23 UTC b62e9f1388178cd17aece8dea748462eaa5ec0ba
5 files changed +27 -31
NOTES.md deleted
-25
@@ -1,25 +0,0 @@
1 -# File browser
2 -- Consider packing toolkit
3 - - if it's a "no", download CDN stuff
4 -
5 -## What GUI lib?
6 -
7 -### Material
8 -- css+js
9 - - https://materializecss.com/
10 -- preact wrapper for [MCW](https://github.com/material-components/material-components-web)
11 - - https://github.com/developit/preact-material-components
12 -
13 -### Others
14 -- https://preactjs.com/about/libraries-addons/
15 - - [fluid](https://unpkg.com/preact-fluid@0.9.1/lib/index.js)
16 - - no module?
17 -
18 -# Study
19 -https://www.tutorialspoint.com/koajs/koajs_quick_guide.htm
20 -
21 -# To do
22 -- vfs
23 - - yaml
24 -- sticky breadcrumbs
25 -- interruption of long requests if client aborted
\ No newline at end of file
dev-notes.md new
+24
@@ -0,0 +1,24 @@
1 +# What GUI lib?
2 +- none?
3 + - would none allow easier customization?
4 +- material
5 + - css+js https://materializecss.com/
6 +
7 +# Study
8 +- https://www.tutorialspoint.com/koajs/koajs_quick_guide.htm
9 +
10 +# To do
11 +- fix dist
12 +- vfs: rename file in source folder
13 +- vfs: hide file in source folder
14 +- fix: crash if vfs is not loadable
15 +- vfs: serve an html for a folder?
16 + - "default" property for vfsNode?
17 +- sticky breadcrumbs
18 +- interruption of long requests if client aborted
19 +- frontend
20 + - don't depend on cdn
21 +- webdav?
22 +- streamable zip archives
23 + - no compression
24 + - resumable?
\ No newline at end of file
src/apis.ts
+1 -1
@@ -12,7 +12,7 @@ type ApiHandlers = Record<string, ApiHandler>
12 export function apiMw(apis: ApiHandlers) : Koa.Middleware {
13 return async (ctx, next) => {
14 const params = ctx.request.body
15 - console.log('API', ctx.method, ctx.path, params)
15 + console.debug('API', ctx.method, ctx.path, params)
16 // @ts-ignore
17 ctx.assert(ctx.path in apis, 404, 'invalid api')
18 const cb = (apis as any)[ctx.path]
src/index.ts
+1 -4
@@ -11,10 +11,7 @@ const PORT = 80
11 const srv = new Koa()
12 srv.use(async (ctx, next) => {
13 // log all requests
14 - console.debug(ctx.request.method, ctx.url)
15 - // prevent cross-dir
16 - // @ts-ignore
17 - ctx.assert(!ctx.originalUrl.includes('..'), 400, 'cross-dir')
14 + console.debug(new Date().toLocaleTimeString(), ctx.request.method, ctx.url)
15 await next()
16 })
17
tests/test.ts
+1 -1
@@ -1,7 +1,7 @@
1 const axios = require('axios')
2
3 describe('file', () => {
4 - itHttp('md', '/NOTES.md', '##')
4 + itHttp('md', '/dev-notes.md', '#')
5 itHttp('frontend', '/', '<body>')
6 itHttp('api.list', '/~/api/file_list', data => Array.isArray(data.list))
7 })