Description
internal/server/ui_routes.go:10:
r.Handle("/static/*", http.StripPrefix("/static/", http.FileServerFS(uiStaticFS)))
For /static/, chi's catch-all matches the empty remainder, StripPrefix yields "", and the file handler rewrites it to "/". Since internal/server/static/ has no index.html, Go falls through to dirList.
Steps to reproduce
| Request | Observed | Expected |
|---|---|---|
GET /static/ |
200 text/html directory index listing app.css, app.js, auth.js, htmx.min.js, lucide.min.js, preload.js, service-worker.js, THIRD_PARTY_LICENSES.txt |
404 |
GET /static |
404 | 404 |
POST /static/app.js |
200 with the file body | 405 |
DELETE /static/app.js |
200 with the file body | 405 |
r.Handle registers all methods, which is why the write verbs return the asset.
Path traversal is not an issue here — chi routes on RawPath and fs.Sub confines reads to the embedded subtree. The problem is enumeration plus the method surface.
Fix
Wrap the file server so a stripped path of "" (or any path ending in /) returns 404, and register with r.Get/r.Head instead of r.Handle.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.