mirror of
https://github.com/profullstack/agentbbs.git
synced 2026-08-13 14:27:27 +00:00
files: per-user public at ~name/public; home = member directory
Re-model the web file host as a file server (not a website host): - Drop the misnamed /site area. A member's public files are now their /me/public subfolder (unix ~/public), served anonymously at ~<name>/public. The rest of /me stays private; only ~name/public is ever exposed. Bare /~name redirects to /~name/public/. - The root / is now a directory of ALL members, each linked to their BBS site (https://<bbs-host>/~name via WebConfig.SiteBase) AND their public files here (~name/public). No longer hides empty members. - Sites/homepages stay on the BBS — files.<host> only links to them. - Usage gauge is just /me again (which includes /me/public). setup.sh + docs updated; tests cover ~name/public browse/download, the bare-~name redirect, empty-member empty-listing, /public-only exposure, and traversal confinement. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
87fb2b4a1f
commit
a2d4817a8e
9 changed files with 203 additions and 166 deletions
20
setup.sh
20
setup.sh
|
|
@ -700,19 +700,21 @@ FILES_SITE="
|
|||
${FILES_DOMAIN} {
|
||||
encode zstd gzip
|
||||
|
||||
# Everything is served by the agentbbs file-manager on loopback. It serves,
|
||||
# all from the same virtual storage as SFTP:
|
||||
# / public directory of members' ~user sites (no auth)
|
||||
# /~<name>[/...] a member's public /site — anon read-only browse + files
|
||||
# A pure file server (NOT a website host — member homepages live on the BBS
|
||||
# at https://${DOMAIN}/~<name>). The agentbbs file-manager on loopback serves:
|
||||
# / directory of all members (links to each one's BBS site
|
||||
# and their public files here) — no auth
|
||||
# /~<name>/public[/] a member's public files folder — anon read-only browse
|
||||
# /public[/...] the shared public area — anon read-only browse + files
|
||||
# (signed in) the member's private /me, their /site, and /public
|
||||
# (signed in) the member's private /me (whose public/ subdir is the
|
||||
# ~name/public surface) and the shared /public
|
||||
# Clean URLs map 1:1 to the SFTP paths, so share links just work:
|
||||
# scp dist.crx files@${FILES_DOMAIN}:/public/extensions/acme/
|
||||
# -> https://${FILES_DOMAIN}/public/extensions/acme/dist.crx
|
||||
# scp index.html files@${FILES_DOMAIN}:/site/
|
||||
# -> https://${FILES_DOMAIN}/~<name>/index.html
|
||||
# The anon surface has no route to a member's private /me (see internal/files
|
||||
# web tests); it is structurally read-only and area-confined.
|
||||
# scp index.html files@${FILES_DOMAIN}:/me/public/
|
||||
# -> https://${FILES_DOMAIN}/~<name>/public/index.html
|
||||
# The anon surface only ever exposes ~name/public, never the rest of a
|
||||
# member's private /me (see internal/files web tests); it is read-only.
|
||||
reverse_proxy http://${FILES_WEB_ADDR}
|
||||
}
|
||||
"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue