finos / perspective

A data visualization and analytics component, especially well-suited for large and/or streaming datasets.
https://perspective.finos.org/
Apache License 2.0
8.38k stars 1.17k forks source link

Disable follow_symlinks #2513

Closed Dreamsorcerer closed 8 months ago

Dreamsorcerer commented 8 months ago

I'm checking that this parameter wasn't set by mistake. The parameter allows a symlink to point to somewhere outside of the static directory. Symlinks that point within the directory will work without enabling this parameter (it's badly named). Therefore enabling this option could make it easy to misconfigure an environment and introduce security issues.

finos-cla-bot[bot] commented 8 months ago

Thank you for your contribution and Welcome to our Open Source Community!

To make sure your pull request is accepted successfully, we ask all our open source contributors to sign a Contributor License Agreement; having reviewed our contributor list, we require a CLA for the following people : (@Dreamsorcerer).

The repository you are attempting to contribute to uses a CLA Bot to check pull requests; in order to be added to the CLA Bot you must follow these instructions.

Thank you once again for your contribution. Let us work with you to make the CLA process quick, easy and efficient so we can move forward with reviewing and accepting your pull request. Feel free to email help@finos.org for any questions.

Dreamsorcerer commented 8 months ago

Change isn't copyrightable, just bypass CLA or create a new PR.

timkpaine commented 8 months ago

https://github.com/finos/perspective/blob/master/CONTRIBUTING.md#guidelines