trackslash
TRACK-56 P1

GET /static/ serves a directory listing and all HTTP methods are accepted

0
All issues

Description

internal/server/ui_routes.go:10:

r.Handle("/static/*", http.StripPrefix("/static/", http.FileServerFS(uiStaticFS)))

For /static/, chi's catch-all matches the empty remainder, StripPrefix yields "", and the file handler rewrites it to "/". Since internal/server/static/ has no index.html, Go falls through to dirList.

Steps to reproduce

Request Observed Expected
GET /static/ 200 text/html directory index listing app.css, app.js, auth.js, htmx.min.js, lucide.min.js, preload.js, service-worker.js, THIRD_PARTY_LICENSES.txt 404
GET /static 404 404
POST /static/app.js 200 with the file body 405
DELETE /static/app.js 200 with the file body 405

r.Handle registers all methods, which is why the write verbs return the asset.

Path traversal is not an issue here — chi routes on RawPath and fs.Sub confines reads to the embedded subtree. The problem is enumeration plus the method surface.

Fix

Wrap the file server so a stripped path of "" (or any path ending in /) returns 404, and register with r.Get/r.Head instead of r.Handle.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.