6 ms·
While I love Go, have we gotten this lazy that we need a package for this? Go does this in 3 lines minimum, like you describe in your blogpost. However, in your
by gabereiser 3y ago
While I love Go, have we gotten this lazy that we need a package for this? Go does this in 3 lines minimum, like you describe in your blogpost. However, in your package you expose the ability to kill your server [0] without any security. That’s a huge vulnerability. I know you’ll say “It’s just a static server, meant for serving static stuff” but it will be indexed by pkg.go.dev, people will use this outside your intent. It is the way. At the very least, use a secret token.
[0] https://github.com/eliben/static-server/blob/3ce83524ed5429860cd602bfc59f67039c9cd83f/internal/server/server.go#L108 https://github.com/eliben/static-server/blob/3ce83524ed54298...
- badrequest 3y agoPeople are allowed to write code/tools that are useful to only themselves. They're also allowed to post about these tools. Nobody is going to make you use them.
- deleted 3y ago[deleted]
- nicoburns 3y agoThese kind of servers are useful for quickly serving a folder of files locally. Security isn't a primary concern for these kind of use cases.
- tgv 3y ago$ python -m http.server
- inChargeOfIT 3y agoAssuming you have python installed on the system, yeah.
- joaomacp 3y agoor the node one: $ npm install http-server $ http-server .
- parminya 3y agoor the go one: $ go run github.com/eliben/static-server@latest
- chrismarlow9 3y agohttps://gist.github.com/willurd/5720255 https://gist.github.com/willurd/5720255
- PinguTS 3y agoThat is the argument of the first MVP by a startup and then it is their onlien product. I have this seen also in automotive. "This is no problem, because this is not connected to the Internet." Then a few years later you have a DefCon presentation "GM hack, you can control the whole car via the Internet".
- gabereiser 3y agoWhere are you hosting your client-side code? Let me see if I can shut it down…
- eliben 3y agoThanks for your comment. I surely hope no one will even consider using this server for anything public-facing :) It's solely for testing on localhost. The shutdown endpoint is used for robust testing; I suppose I can hide it a bit more, like using an environment variable or something.
- d-z-m 3y agoIt's fine the way it is IMO. However, it might be worth caveating in the README that it's for local testing only, the same way you do in your blog post. Mainly because of the shutdown endpoint, but also that the -cors flag returns "Access-Control-Allow-Origin: *" exposing you to arbitrary cross origin requests.
- gabereiser 3y agoJust check a header for a secret key you generate when you startup. Easy peasy. This keeps you able to call it for testing (granted you read from stdout or passed the key to tests as a variable). Then some scripto ransomware User from Omgodisztan doesn’t shutdown your server from the tent he’s camped in with Starlink.
- eliben 3y agoThis is done now, thanks for the suggestion
- midwit 3y agoA simple middleware hook for http basic auth :)
- jjice 3y ago> I know you’ll say “It’s just a static server, meant for serving static stuff” but it will be indexed by pkg.go.dev, people will use this outside your intent. While true, I don't think the author should refrain from making code available based on the potential negatives from others using code they didn't even bother to read the documentation for.
- gabereiser 3y agoYou’re right, however, due to the nature of the go ecosystem, someone will use it - host their react app with it - and expose an endpoint that could shutdown their server. I think that warrants being called out for.
- xcdzvyn 3y agorm -rf / Need I be called out, now?