fix: publish the directory page readable by the web server
This commit is contained in:
parent
1cf6e30908
commit
92813ccbe3
2 changed files with 18 additions and 0 deletions
|
|
@ -210,6 +210,10 @@ def write_directory(target: str, rows: list[sqlite3.Row]) -> list[str]:
|
||||||
)
|
)
|
||||||
temporary = destination.with_name("." + destination.name + ".tmp")
|
temporary = destination.with_name("." + destination.name + ".tmp")
|
||||||
temporary.write_bytes(text)
|
temporary.write_bytes(text)
|
||||||
|
# The web server reads this file straight off disk as another user, so
|
||||||
|
# it is made readable on purpose. The service runs with a private umask
|
||||||
|
# to keep the database to itself, and that would otherwise apply here.
|
||||||
|
temporary.chmod(0o644)
|
||||||
os.replace(temporary, destination)
|
os.replace(temporary, destination)
|
||||||
|
|
||||||
warnings = [str(f) for f in result.warnings]
|
warnings = [str(f) for f in result.warnings]
|
||||||
|
|
|
||||||
|
|
@ -344,6 +344,20 @@ def test_a_hostile_title_is_escaped_and_stripped(connection, tmp_path):
|
||||||
assert validate_bytes(target.read_bytes()).conforms
|
assert validate_bytes(target.read_bytes()).conforms
|
||||||
|
|
||||||
|
|
||||||
|
def test_the_directory_page_is_readable_by_the_web_server(connection, tmp_path):
|
||||||
|
"""It is served off disk by another user, whatever umask the service has."""
|
||||||
|
import os
|
||||||
|
import stat
|
||||||
|
|
||||||
|
target = tmp_path / "directory.html"
|
||||||
|
old_umask = os.umask(0o077)
|
||||||
|
try:
|
||||||
|
pages.write_directory(str(target), db.listed(connection))
|
||||||
|
finally:
|
||||||
|
os.umask(old_umask)
|
||||||
|
assert stat.S_IMODE(target.stat().st_mode) == 0o644
|
||||||
|
|
||||||
|
|
||||||
def test_an_empty_directory_still_conforms(connection, tmp_path):
|
def test_an_empty_directory_still_conforms(connection, tmp_path):
|
||||||
from mews.lint import validate_bytes
|
from mews.lint import validate_bytes
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue