@rdeavila commented on GitHub:
I agree with @monkz. When we send a file, the site returns the file URL like https://transfer.sh/<random_code>/<filename>, right?
Why not return two URLs, one…
@nl5887 commented on GitHub:
Exactly why we haven't implemented it yet. I can imagine returning an extra delete header, but that won't be visible for most people. Especially not the people that…
@pepa65 commented on GitHub:
Great idea, but definitely prefer the first form:
https://transfer.sh/<random_code>/<filename>
https://transfer.sh/delete/<another_very_different_random_code>/<…
@monkz commented on GitHub:
An attacker has access to multiple IP addresses and introducing ratelimits is the same as introducing a denial-of-service attack vector. @ribamar-santarosa : so your…
@ribamar-santarosa commented on GitHub:
how did you get to that conclusion? how can they take advantage of having multiple IPs to change or fake the IP of the creation of the file? And how about…
@monkz commented on GitHub:
I would opt for the first as default, and the second may be returned if /json is at the end of the url.
This would be analog to the "Scan for malware"-example.
Bu…
@ribamar-santarosa commented on GitHub:
Can't you use the creation time (or another file attribute, or another creation attribute, like IP of upload ) as a simple pin code to delete the file? 3…
@macblazer commented on GitHub:
I've generated an appropriate CSV file from the data in the CC GPOS Control Mappings.pdf at the above link. Running the scripts/generate_mapping.py on it…
@robertgendler commented on GitHub:
Closing issue. Without an owner of the baseline, we won't be implementing this.
@macblazer commented on GitHub:
For whoever wants to pick this up, here is the contents of the mapping file. I named it CommonCriteria_GPOS_PP_421.csv.
pp_os_v4.2.1,800-53r5
FCS_CKM.1,…
@monkz commented on GitHub:
3 attempts from the same IP unable to hit the code at least with hour precision -- functionality ban.
You can use arbitrary numbers of IP addresses. This allows…
@monkz commented on GitHub:
Usability thoughts about my post above:
Hosters should've the possibility to set defaults and limitations to parameters that are available in request headers, that…
@Anachron commented on GitHub:
@monkz why not let the user specify a deletion secret himself (which is optional) and can be passed as POST param?
@golbiga commented on GitHub:
The fix is in master, please test. Closing issue.
@golbiga commented on GitHub:
This has been fixed in the 0.9_prerelease branch, it will be included in the release.
Thanks for reporting it.