summaryrefslogtreecommitdiff
path: root/README.md
diff options
context:
space:
mode:
authorSomhairle H. Marisol <[email protected]>2026-09-21 07:37:51 +0800
committerSomhairle H. Marisol <[email protected]>2026-09-21 07:37:51 +0800
commit56800fbbd4488db20abd4f44f0d39e48599be0ab (patch)
treef32c815543000daf4c2ad33e534bb806e0555c3f /README.md
parente8eebe49407de8947bf509d5cf04d9080ee4edf7 (diff)
downloadsomhairles-dream-fsharp-56800fbbd4488db20abd4f44f0d39e48599be0ab.tar.gz
Secure artifact serving: manifest/checkpoint membership, hash validation, link rejection
Diffstat (limited to 'README.md')
-rw-r--r--README.md10
1 files changed, 9 insertions, 1 deletions
diff --git a/README.md b/README.md
index 977c984..0f126db 100644
--- a/README.md
+++ b/README.md
@@ -122,7 +122,15 @@ Routes used by the frontend: `POST /api/runs/start`,
`GET /api/artifacts/manifest`, `GET /api/artifacts/file`, and
`GET /api/artifacts/steps?projectId=...&runId=...&path=steps/<step>.glb`
(serve a step GLB while a run is still active; `.glb` files under `steps/`
-only, traversal-guarded). The server binds to the ASP.NET default (add
+only, traversal-guarded). Artifact serving is integrity-checked: `file`
+serves only paths published in the verified run manifest (logs, the
+manifest itself, and stray files are never exposed), `steps` serves only
+checkpointed GLBs (manifest members for completed runs), and every served
+stream is hashed against its recorded SHA-256 and byte count at request
+time. Filesystem links inside a run directory (file or intermediate
+directory symlinks/junctions) are rejected with `400`; hash or byte-count
+deviations return `409`, and manifest failures surface as `500`. The
+server binds to the ASP.NET default (add
`--urls http://127.0.0.1:8099` to match the legacy port).
## CLI