4 ms·
Serving a 'text file' from a web server module seems to overcomplicate things in my view. More code || complexity == greater likelihood of bugs (including secu
by mjthompson 6y ago
Serving a 'text file' from a web server module seems to overcomplicate things in my view.
More code || complexity == greater likelihood of bugs (including security bugs).
As ironic as a security bug in a security.txt serving module would be, it's probably best we avoid that possibility and let the ordinary, highly scrutinised file serving code handle it instead.
- IgorPartola 6y agoIf you want adoption, make it so easy that it’s harder to not include it. If you run an application, it will take lines of config to serve this file anyways. Might as well make it easy. And if you can’t make a bug free module that writes out 5 lines into a static file… probably shouldn’t be defining web standards.
- nexuist 6y agoConversely, if you are providing a web based service on the public Internet and can't be assed to drop a five line text file in your home directory, you probably should not be running a server on the public Internet.