3 ms·
Soon: google for 'inurl:github_update.php' and click each result. Better alternative: use something like Capistrano to automate deployments. It's not Heroku-st
by generalk 16y ago
Soon: google for 'inurl:github_update.php' and click each result.
Better alternative: use something like Capistrano to automate deployments. It's not Heroku-style automatic after a push, but it's pretty close.
Still, points for ingenuity.
- zbanks 16y agogithub_update.php wouldn't be linked to by any of your pages, so it shouldn't show up in the google index. You could also force it to accept some password as a GET parameter for a wee bit more security. I agree though, this is still a really simple way to automate deployment.
- markchristian 16y agoNote that I didn't actually call my own github_update.php, and there's no reason for anyone else to — call it whatever you'd like.
- Udo 16y agoThere are lots of web apps that use update mechanisms like this one. Back in the bad old days, I remember writing something that synced code files by using some convoluted homebrew json protocol. Anyway, the point is: this kind of functionality is normally restricted by the web app, usually requiring admin privileges or some form of authentication. For example, at work, we have a similar function that pulls down the current SVN repository onto the web servers. We've been doing this for years, it works great - but that doesn't mean people can just call these URLs from the outside. I also believe choosing an obfuscating name for the update file is not sufficiently secure.