diff options
| author | Somhairle H. Marisol <[email protected]> | 2026-09-21 07:37:51 +0800 |
|---|---|---|
| committer | Somhairle H. Marisol <[email protected]> | 2026-09-21 07:37:51 +0800 |
| commit | 56800fbbd4488db20abd4f44f0d39e48599be0ab (patch) | |
| tree | f32c815543000daf4c2ad33e534bb806e0555c3f /README.md | |
| parent | e8eebe49407de8947bf509d5cf04d9080ee4edf7 (diff) | |
| download | somhairles-dream-fsharp-56800fbbd4488db20abd4f44f0d39e48599be0ab.tar.gz | |
Secure artifact serving: manifest/checkpoint membership, hash validation, link rejection
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 10 |
1 files changed, 9 insertions, 1 deletions
@@ -122,7 +122,15 @@ Routes used by the frontend: `POST /api/runs/start`, `GET /api/artifacts/manifest`, `GET /api/artifacts/file`, and `GET /api/artifacts/steps?projectId=...&runId=...&path=steps/<step>.glb` (serve a step GLB while a run is still active; `.glb` files under `steps/` -only, traversal-guarded). The server binds to the ASP.NET default (add +only, traversal-guarded). Artifact serving is integrity-checked: `file` +serves only paths published in the verified run manifest (logs, the +manifest itself, and stray files are never exposed), `steps` serves only +checkpointed GLBs (manifest members for completed runs), and every served +stream is hashed against its recorded SHA-256 and byte count at request +time. Filesystem links inside a run directory (file or intermediate +directory symlinks/junctions) are rejected with `400`; hash or byte-count +deviations return `409`, and manifest failures surface as `500`. The +server binds to the ASP.NET default (add `--urls http://127.0.0.1:8099` to match the legacy port). ## CLI |
