Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent wrangler pages dev from serving asset files outside of the build output directory #3498

Conversation

GregBrimble
Copy link
Member

Fixes https://cflare.co/24935

What this PR solves / how to test:

Ensures only files from within the build output directory can be served in wrangler pages dev.

Author has included the following, where applicable:

Reviewer is to perform the following, as applicable:

  • Checked for inclusion of relevant tests
  • Checked for inclusion of a relevant changeset
  • Checked for creation of associated docs updates
  • Manually pulled down the changes and spot-tested

@GregBrimble GregBrimble requested review from a team as code owners June 20, 2023 17:17
@changeset-bot
Copy link

changeset-bot bot commented Jun 20, 2023

🦋 Changeset detected

Latest commit: 2bd2283

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
wrangler Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions
Copy link
Contributor

A wrangler prerelease is available for testing. You can install this latest build in your project with:

npm install --save-dev https://prerelease-registry.devprod.cloudflare.dev/workers-sdk/runs/5325524919/npm-package-wrangler-3498

You can reference the automatically updated head of this PR with:

npm install --save-dev https://prerelease-registry.devprod.cloudflare.dev/workers-sdk/prs/3498/npm-package-wrangler-3498

Or you can use npx with this latest build directly:

npx https://prerelease-registry.devprod.cloudflare.dev/workers-sdk/runs/5325524919/npm-package-wrangler-3498 dev path/to/script.js
Additional artifacts:
npm install https://prerelease-registry.devprod.cloudflare.dev/workers-sdk/runs/5325524919/npm-package-cloudflare-pages-shared-3498

Note that these links will no longer work once the GitHub Actions artifact expires.

@codecov
Copy link

codecov bot commented Jun 20, 2023

Codecov Report

Merging #3498 (2bd2283) into main (a72dc0a) will increase coverage by 0.04%.
The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #3498      +/-   ##
==========================================
+ Coverage   75.18%   75.23%   +0.04%     
==========================================
  Files         183      183              
  Lines       11055    11064       +9     
  Branches     2904     2906       +2     
==========================================
+ Hits         8312     8324      +12     
+ Misses       2743     2740       -3     

see 4 files with indirect coverage changes

@penalosa penalosa merged commit fddffdf into main Jun 20, 2023
@penalosa penalosa deleted the prevent-pages-dev-from-serving-asset-files-outside-of-build-directory branch June 20, 2023 17:49
@github-actions github-actions bot mentioned this pull request Jun 20, 2023
lrapoport-cf pushed a commit that referenced this pull request Aug 11, 2023
@GregBrimble GregBrimble mentioned this pull request Aug 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants