Restrain public files to the public/ folder
As raised by Adriaan (@agboom), the .github-user-tokens.json file was incorrectly exposed, causing the risk of users' GitHub tokens to be used by other entities for the purpose of increasing their rate limits by pretending to be shields.io.
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
<p align="center">
|
||||
<img src="https://rawgit.com/badges/shields/master/logo.svg"
|
||||
<img src="https://rawgit.com/badges/shields/master/public/logo.svg"
|
||||
height="130">
|
||||
</p>
|
||||
<p align="center">
|
||||
|
||||
1
public/favicon.png
Symbolic link
1
public/favicon.png
Symbolic link
@@ -0,0 +1 @@
|
||||
../favicon.png
|
||||
1
public/index.html
Symbolic link
1
public/index.html
Symbolic link
@@ -0,0 +1 @@
|
||||
../index.html
|
||||
|
Before Width: | Height: | Size: 3.4 KiB After Width: | Height: | Size: 3.4 KiB |
1
public/try.html
Symbolic link
1
public/try.html
Symbolic link
@@ -0,0 +1 @@
|
||||
../try.html
|
||||
@@ -3,9 +3,10 @@ var serverPort = +process.env.PORT || +process.argv[2] || (secureServer? 443: 80
|
||||
var bindAddress = process.env.BIND_ADDRESS || process.argv[3] || '::';
|
||||
var infoSite = process.env.INFOSITE || "http://shields.io";
|
||||
var githubApiUrl = process.env.GITHUB_URL || 'https://api.github.com';
|
||||
var path = require('path');
|
||||
var Camp = require('camp');
|
||||
var camp = Camp.start({
|
||||
documentRoot: __dirname,
|
||||
documentRoot: path.join(__dirname, 'public'),
|
||||
port: serverPort,
|
||||
hostname: bindAddress,
|
||||
secure: secureServer
|
||||
|
||||
Reference in New Issue
Block a user