svnlabs / google-caja

Automatically exported from code.google.com/p/google-caja
0 stars 1 forks source link

test server should be more locked down #1966

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
The web server started by 'ant runtests' / 'ant brserve' permits more than it 
needs to:

* It allows access from the network. Localhost would be a better _default_.

* It serves all files in the project root, hence including .svn or .git. In the 
event that network access is permitted, hiding .git would prevent reading 
history information which could include undisclosed draft security patches and 
such.

(Of course, if the server is accessible then the current files it's serving 
show the current work as well, but VCS data is more slurpable.)

Original issue reported on code.google.com by kpreid@google.com on 14 Apr 2015 at 4:56