fix: publish the directory page readable by the web server

This commit is contained in:
randogoth 2026-10-11 16:39:39 +03:00
parent 1cf6e30908
commit 92813ccbe3
2 changed files with 18 additions and 0 deletions

View file

@ -210,6 +210,10 @@ def write_directory(target: str, rows: list[sqlite3.Row]) -> list[str]:
)
temporary = destination.with_name("." + destination.name + ".tmp")
temporary.write_bytes(text)
# The web server reads this file straight off disk as another user, so
# it is made readable on purpose. The service runs with a private umask
# to keep the database to itself, and that would otherwise apply here.
temporary.chmod(0o644)
os.replace(temporary, destination)
warnings = [str(f) for f in result.warnings]

View file

@ -344,6 +344,20 @@ def test_a_hostile_title_is_escaped_and_stripped(connection, tmp_path):
assert validate_bytes(target.read_bytes()).conforms
def test_the_directory_page_is_readable_by_the_web_server(connection, tmp_path):
"""It is served off disk by another user, whatever umask the service has."""
import os
import stat
target = tmp_path / "directory.html"
old_umask = os.umask(0o077)
try:
pages.write_directory(str(target), db.listed(connection))
finally:
os.umask(old_umask)
assert stat.S_IMODE(target.stat().st_mode) == 0o644
def test_an_empty_directory_still_conforms(connection, tmp_path):
from mews.lint import validate_bytes