René's URL Explorer Experiment


Title: doc: document dangerous symlink behavior by tniessen · Pull Request #49154 · nodejs/node · GitHub

Open Graph Title: doc: document dangerous symlink behavior by tniessen · Pull Request #49154 · nodejs/node

X Title: doc: document dangerous symlink behavior by tniessen · Pull Request #49154 · nodejs/node

Description: Much earlier, a design decision was made that the permission model should not prevent following symbolic links to presumably inaccessible locations. Recently, after some back and forth, it had been...

Open Graph Description: Much earlier, a design decision was made that the permission model should not prevent following symbolic links to presumably inaccessible locations. Recently, after some back and forth, it had been...

X Description: Much earlier, a design decision was made that the permission model should not prevent following symbolic links to presumably inaccessible locations. Recently, after some back and forth, it had been...

Opengraph URL: https://github.com/nodejs/node/pull/49154

X: @github

direct link

Domain: github.com

route-pattern/_view_fragments/voltron/pull_requests/show/:user_id/:repository/:id/pull_request_layout(.:format)
route-controllervoltron_pull_requests_fragments
route-actionpull_request_layout
fetch-noncev2:6ce45630-930b-7351-ad04-280283f69823
current-catalog-service-hashae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b
request-id9FD0:1ED5B9:3F3622:5572BE:6969D140
html-safe-nonce173b40c8a9a47cb9d52568149b1017dd578f995d160c81e59d1886273d21b15e
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5RkQwOjFFRDVCOTozRjM2MjI6NTU3MkJFOjY5NjlEMTQwIiwidmlzaXRvcl9pZCI6IjQ3MzgwMzY3NTUzODQwOTUwNDAiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ==
visitor-hmac36fc2ec36c258fea08ac9585aee5c121b0339a595ed285e4d9ea3cecc12f15cf
hovercard-subject-tagpull_request:1473528310
github-keyboard-shortcutsrepository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///voltron/pull_requests_fragments/pull_request_layout
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/_view_fragments/voltron/pull_requests/show/nodejs/node/49154/pull_request_layout
twitter:imagehttps://opengraph.githubassets.com/1df7a50ffecce537a085f9ea5976f1f1936beb81618cea804035e31e07ab9481/nodejs/node/pull/49154
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/1df7a50ffecce537a085f9ea5976f1f1936beb81618cea804035e31e07ab9481/nodejs/node/pull/49154
og:image:altMuch earlier, a design decision was made that the permission model should not prevent following symbolic links to presumably inaccessible locations. Recently, after some back and forth, it had been...
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
og:author:usernametniessen
hostnamegithub.com
expected-hostnamegithub.com
Noneacedec8b5f975d9e3d494ddd8f949b0b8a0de59d393901e26f73df9dcba80056
turbo-cache-controlno-preview
go-importgithub.com/nodejs/node git https://github.com/nodejs/node.git
octolytics-dimension-user_id9950313
octolytics-dimension-user_loginnodejs
octolytics-dimension-repository_id27193779
octolytics-dimension-repository_nwonodejs/node
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id27193779
octolytics-dimension-repository_network_root_nwonodejs/node
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release83c08c21cdda978090dc44364b71aa5bc6dcea79
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/nodejs/node/pull/49154#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fnodejs%2Fnode%2Fpull%2F49154
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fnodejs%2Fnode%2Fpull%2F49154
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fpull_requests_fragments%2Fpull_request_layout&source=header-repo&source_repo=nodejs%2Fnode
Reloadhttps://github.com/nodejs/node/pull/49154
Reloadhttps://github.com/nodejs/node/pull/49154
Reloadhttps://github.com/nodejs/node/pull/49154
nodejs https://github.com/nodejs
nodehttps://github.com/nodejs/node
Please reload this pagehttps://github.com/nodejs/node/pull/49154
Notifications https://github.com/login?return_to=%2Fnodejs%2Fnode
Fork 34.4k https://github.com/login?return_to=%2Fnodejs%2Fnode
Star 115k https://github.com/login?return_to=%2Fnodejs%2Fnode
Code https://github.com/nodejs/node
Issues 1.7k https://github.com/nodejs/node/issues
Pull requests 697 https://github.com/nodejs/node/pulls
Actions https://github.com/nodejs/node/actions
Projects 3 https://github.com/nodejs/node/projects
Security Uh oh! There was an error while loading. Please reload this page. https://github.com/nodejs/node/security
Please reload this pagehttps://github.com/nodejs/node/pull/49154
Insights https://github.com/nodejs/node/pulse
Code https://github.com/nodejs/node
Issues https://github.com/nodejs/node/issues
Pull requests https://github.com/nodejs/node/pulls
Actions https://github.com/nodejs/node/actions
Projects https://github.com/nodejs/node/projects
Security https://github.com/nodejs/node/security
Insights https://github.com/nodejs/node/pulse
Sign up for GitHub https://github.com/signup?return_to=%2Fnodejs%2Fnode%2Fissues%2Fnew%2Fchoose
terms of servicehttps://docs.github.com/terms
privacy statementhttps://docs.github.com/privacy
Sign inhttps://github.com/login?return_to=%2Fnodejs%2Fnode%2Fissues%2Fnew%2Fchoose
Jump to bottomhttps://github.com/nodejs/node/pull/49154#issue-comment-box
nodejs-github-bothttps://github.com/nodejs-github-bot
nodejs:mainhttps://github.com/nodejs/node/tree/main
tniessen:doc-symlink-dangerhttps://github.com/tniessen/node/tree/doc-symlink-danger
doc: document dangerous symlink behavior https://github.com/nodejs/node/pull/49154#top
nodejs-github-bothttps://github.com/nodejs-github-bot
nodejs:mainhttps://github.com/nodejs/node/tree/main
tniessen:doc-symlink-dangerhttps://github.com/tniessen/node/tree/doc-symlink-danger
Conversation 12 https://github.com/nodejs/node/pull/49154
Commits 1 https://github.com/nodejs/node/pull/49154/commits
Checks 0 https://github.com/nodejs/node/pull/49154/checks
Files changed https://github.com/nodejs/node/pull/49154/files
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.co/hiddenchars
https://github.com/nodejs/node/pull/{{ revealButtonHref }}
https://github.com/tniessen
tniessenhttps://github.com/tniessen
Aug 13, 2023https://github.com/nodejs/node/pull/49154#issue-1848777205
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://hackerone.com/reports/1961655https://hackerone.com/reports/1961655
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/nodejs-github-bot
nodejs-github-bothttps://github.com/nodejs-github-bot
Aug 13, 2023https://github.com/nodejs/node/pull/49154#issuecomment-1676489342
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/nodejs-github-bot
nodejs-github-bothttps://github.com/nodejs-github-bot
doc https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3Adoc
Aug 13, 2023https://github.com/nodejs/node/pull/49154#event-10080783165
https://github.com/tniessen
tniessenhttps://github.com/tniessen
Aug 13, 2023 https://github.com/nodejs/node/pull/49154#ref-pullrequest-1848758762
doc: clarify pm limitations and include symlink statement #49153 https://github.com/nodejs/node/pull/49153
https://github.com/RafaelGSS
RafaelGSShttps://github.com/RafaelGSS
August 14, 2023 00:35https://github.com/nodejs/node/pull/49154#event-10080953239
https://github.com/RafaelGSS
RafaelGSShttps://github.com/RafaelGSS
Aug 14, 2023 https://github.com/nodejs/node/pull/49154#pullrequestreview-1575942646
View reviewed changes https://github.com/nodejs/node/pull/49154/files
doc/api/permissions.mdhttps://github.com/nodejs/node/pull/49154/files#diff-1b4f0b629d3e46a29fe679cff7053c158a9800aab0156d2d67004ef0177c42fd
Please reload this pagehttps://github.com/nodejs/node/pull/49154
doc/api/permissions.mdhttps://github.com/nodejs/node/pull/49154/files#diff-1b4f0b629d3e46a29fe679cff7053c158a9800aab0156d2d67004ef0177c42fd
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/RafaelGSS
RafaelGSShttps://github.com/RafaelGSS
Sep 7, 2023https://github.com/nodejs/node/pull/49154#issuecomment-1710603188
@tniessenhttps://github.com/tniessen
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/RafaelGSS
RafaelGSShttps://github.com/RafaelGSS
permission https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3Apermission
Sep 7, 2023https://github.com/nodejs/node/pull/49154#event-10310600529
https://github.com/tniessen
tniessenhttps://github.com/tniessen
Sep 22, 2023https://github.com/nodejs/node/pull/49154#issuecomment-1731380813
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/tniessen
doc: document dangerous symlink behaviorhttps://github.com/nodejs/node/pull/49154/commits/1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
1fd427bhttps://github.com/nodejs/node/pull/49154/commits/1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
https://hackerone.com/reports/1961655https://hackerone.com/reports/1961655
https://github.com/tniessen
tniessenhttps://github.com/tniessen
force-pushedhttps://github.com/nodejs/node/compare/05b0b7b8e2bca8dd5312d4d3451fabf9dc2f906c..1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
05b0b7bhttps://github.com/nodejs/node/commit/05b0b7b8e2bca8dd5312d4d3451fabf9dc2f906c
1fd427bhttps://github.com/nodejs/node/commit/1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
Compare https://github.com/nodejs/node/compare/05b0b7b8e2bca8dd5312d4d3451fabf9dc2f906c..1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
September 22, 2023 13:09https://github.com/nodejs/node/pull/49154#event-10447269660
https://github.com/mcollina
mcollinahttps://github.com/mcollina
Sep 22, 2023https://github.com/nodejs/node/pull/49154#issuecomment-1731398983
@tniessenhttps://github.com/tniessen
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/tniessen
tniessenhttps://github.com/tniessen
Sep 22, 2023https://github.com/nodejs/node/pull/49154#issuecomment-1731414836
@mcollinahttps://github.com/mcollina
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/benjamingr
benjamingrhttps://github.com/benjamingr
Sep 23, 2023 https://github.com/nodejs/node/pull/49154#pullrequestreview-1640910331
View reviewed changes https://github.com/nodejs/node/pull/49154/files/1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
https://github.com/tniessen
tniessenhttps://github.com/tniessen
author ready https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3A%22author%20ready%22
Sep 24, 2023https://github.com/nodejs/node/pull/49154#event-10454831484
https://github.com/aduh95
aduh95https://github.com/aduh95
Sep 29, 2023 https://github.com/nodejs/node/pull/49154#pullrequestreview-1650546556
View reviewed changes https://github.com/nodejs/node/pull/49154/files/1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
https://github.com/tniessen
tniessenhttps://github.com/tniessen
commit-queue https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3Acommit-queue
Sep 29, 2023https://github.com/nodejs/node/pull/49154#event-10510283763
https://github.com/nodejs-github-bot
nodejs-github-bothttps://github.com/nodejs-github-bot
commit-queue https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3Acommit-queue
Sep 29, 2023https://github.com/nodejs/node/pull/49154#event-10510350857
https://github.com/nodejs-github-bot
nodejs-github-bothttps://github.com/nodejs-github-bot
1dc0667https://github.com/nodejs/node/commit/1dc0667aa6096f10c5f95471dfe27e78db1dafd5
Sep 29, 2023https://github.com/nodejs/node/pull/49154#event-10510351677
https://github.com/nodejs-github-bot
nodejs-github-bothttps://github.com/nodejs-github-bot
Sep 29, 2023https://github.com/nodejs/node/pull/49154#issuecomment-1740743227
1dc0667https://github.com/nodejs/node/commit/1dc0667aa6096f10c5f95471dfe27e78db1dafd5
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/RafaelGSS
RafaelGSShttps://github.com/RafaelGSS
Oct 9, 2023 https://github.com/nodejs/node/pull/49154#ref-pullrequest-1912846720
2023-10-17, Version 21.0.0 (Current) #49870 https://github.com/nodejs/node/pull/49870
alexfernandezhttps://github.com/alexfernandez
Nov 1, 2023 https://github.com/nodejs/node/pull/49154#ref-commit-6ce3952
https://github.com/tniessen
https://github.com/alexfernandez
doc: document dangerous symlink behaviorhttps://github.com/alexfernandez/node/commit/6ce3952dd68c51787aab13e575b82a4b75b19c3a
6ce3952https://github.com/alexfernandez/node/commit/6ce3952dd68c51787aab13e575b82a4b75b19c3a
https://hackerone.com/reports/1961655https://hackerone.com/reports/1961655
nodejs#49154https://github.com/nodejs/node/pull/49154
targoshttps://github.com/targos
Nov 11, 2023 https://github.com/nodejs/node/pull/49154#ref-commit-24458e2
https://github.com/tniessen
https://github.com/targos
doc: document dangerous symlink behaviorhttps://github.com/nodejs/node/commit/24458e2ac33f88cf7281d767e02c2ceb1e2605fa
24458e2https://github.com/nodejs/node/commit/24458e2ac33f88cf7281d767e02c2ceb1e2605fa
https://hackerone.com/reports/1961655https://hackerone.com/reports/1961655
#49154https://github.com/nodejs/node/pull/49154
https://github.com/targos
targoshttps://github.com/targos
Nov 12, 2023 https://github.com/nodejs/node/pull/49154#ref-pullrequest-1989293723
v20.10.0 release proposal #50682 https://github.com/nodejs/node/pull/50682
https://github.com/juanarbol
juanarbolhttps://github.com/juanarbol
Dec 6, 2023 https://github.com/nodejs/node/pull/49154#ref-pullrequest-2029497346
2023-12-06, N|Solid v5.0.1 Iron Release nodesource/nsolid#41 https://github.com/nodesource/nsolid/pull/41
debadree25https://github.com/debadree25
Apr 15, 2024 https://github.com/nodejs/node/pull/49154#ref-commit-9c5d249
https://github.com/tniessen
https://github.com/debadree25
doc: document dangerous symlink behaviorhttps://github.com/debadree25/node/commit/9c5d249ef1eb218e414a08a11af0622c6f83730a
9c5d249https://github.com/debadree25/node/commit/9c5d249ef1eb218e414a08a11af0622c6f83730a
https://hackerone.com/reports/1961655https://hackerone.com/reports/1961655
nodejs#49154https://github.com/nodejs/node/pull/49154
Sign up for freehttps://github.com/join?source=comment-repo
Sign in to commenthttps://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fnodejs%2Fnode%2Fpull%2F49154
https://github.com/mhdawson
mhdawson https://github.com/mhdawson
https://github.com/nodejs/node/pull/49154/files/05b0b7b8e2bca8dd5312d4d3451fabf9dc2f906c
https://github.com/RafaelGSS
RafaelGSS https://github.com/RafaelGSS
https://github.com/nodejs/node/pull/49154/files/05b0b7b8e2bca8dd5312d4d3451fabf9dc2f906c
https://github.com/benjamingr
benjamingr https://github.com/benjamingr
https://github.com/nodejs/node/pull/49154/files/1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
https://github.com/aduh95
aduh95 https://github.com/aduh95
https://github.com/nodejs/node/pull/49154/files/1fd427b9c46a4b6daa2ea7cbb0830dac47f8cd68
https://github.com/lirantal
lirantal https://github.com/lirantal
https://github.com/nodejs/node/pull/49154/files/05b0b7b8e2bca8dd5312d4d3451fabf9dc2f906c
author ready https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3A%22author%20ready%22
doc https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3Adoc
permission https://github.com/nodejs/node/issues?q=state%3Aopen%20label%3Apermission
Please reload this pagehttps://github.com/nodejs/node/pull/49154
https://github.com/tniessen
https://github.com/nodejs-github-bot
https://github.com/RafaelGSS
https://github.com/mcollina
https://github.com/lirantal
https://github.com/benjamingr
https://github.com/mhdawson
https://github.com/aduh95
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.