2016-10-25 15:55:25 +01:00
|
|
|
--- a/src/web_client.c.orig
|
|
|
|
+++ b/src/web_client.c
|
2017-09-17 14:22:24 +01:00
|
|
|
@@ -302,7 +302,7 @@
|
|
|
|
buffer_strcat_htmlescape(w->response.data, webfilename);
|
2016-10-25 15:55:25 +01:00
|
|
|
return 404;
|
|
|
|
}
|
|
|
|
-
|
|
|
|
+#if 0
|
|
|
|
// check if the file is owned by expected user
|
|
|
|
if(stat.st_uid != web_files_uid()) {
|
|
|
|
error("%llu: File '%s' is owned by user %u (expected user %u). Access Denied.", w->id, webfilename, stat.st_uid, web_files_uid());
|
2017-09-17 14:22:24 +01:00
|
|
|
@@ -320,7 +320,7 @@
|
|
|
|
buffer_strcat_htmlescape(w->response.data, webfilename);
|
2016-10-25 15:55:25 +01:00
|
|
|
return 403;
|
|
|
|
}
|
|
|
|
-
|
|
|
|
+#endif
|
|
|
|
if((stat.st_mode & S_IFMT) == S_IFDIR) {
|
|
|
|
snprintfz(webfilename, FILENAME_MAX, "%s/index.html", filename);
|
|
|
|
return mysendfile(w, webfilename);
|