@robertgendler commented on GitHub:
@akegerreis do you have a suggestion on how this should appear in the project?
A note in supplemental where unmapped users is talked about? A separate rule?
@akegerreis commented on GitHub:
@robertgendler we have this slated to go into the supplemental for our April release of the STIG.
@isaacatmann commented on GitHub:
Update better detection
Detection:
sqlite3 ~/Library/Safari/PerSitePreferences.db 'select default_value from default_preferences WHERE preference="PerSit…
@jmahlman commented on GitHub:
CIS has updated the guidance for this rule and moved it to a manual audit. Since the config profile does not work, we have removed the rule from the Sequoia branch…
@robertgendler commented on GitHub:
Sorry it took a while to come around to this.
Testing with macOS 14.5 and the profile installed and testing your website. It is blocking popups for me. Now…
@isaacatmann commented on GitHub:
Update, resolution is as follows:
@paolafrancesca commented on GitHub:
@stek29 I think that instead of disabling the inline handler we could sanitize the html content using bluemonday (https://github.com/microcosm-cc/bluemonday). …
@stek29 commented on GitHub:
Is content type sanitized in any way? MIME types are case insensitive afaik, and from what i see it’s not lowercased anywhere
@paolafrancesca commented on GitHub:
you are right @stek29 : https://github.com/dutchcoders/transfer.sh/blob/master/server/handlers.go#L476-L480
I forgot that we use mime.TypeByExtension…
@paolafrancesca commented on GitHub:
hello @sicenul
you have to set the following two ENV variables:
HTTP_AUTH_USER, HTTP_AUTH_PASS
https://github.com/dutchcoders/transfer.sh/blob/master/c…
@sicenul commented on GitHub:
great it work, thanks for your fast response.
@stek29 commented on GitHub:
@aspacca your solution seems good enough (.Contains html) I’d still prefer to have an option to disable inline handler completely tbh, but yeah, it’s good enough
@stefanbenten commented on GitHub:
@JustAnotherArchivist Did you see the example alias/function for the linux terminal? That would essentially be what you want for manual usage. Please correct me…
@soulofmischief commented on GitHub:
@aspacca https://github.com/dutchcoders/transfer.sh-web/pull/35