-
Notifications
You must be signed in to change notification settings - Fork 102
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
The sqlpage folder can be read by HTTP client requests #89
Comments
Thank you very much for the report. The check was removed during a refactoring and we missed it because we didn't have a test for it. I'll release a new version today. |
Just released v0.11.1 |
I published an advisory and requested a CVE, where you will be credited. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
With the browser, we can download the files in the sqlpage folder. For example, it's possible to read the
sqlpage.json
configuration file. It's a security problem. The sqlpage folder must be keep hidden.It's possible to set rewrite rules on the proxy side to block the download. But, I think that it will be cool to filter url in sqlpage server.
The text was updated successfully, but these errors were encountered: