Skip to content

Merge https://github.com/filebrowser/filebrowser:master (be23ab3) into oadp-dev#18

Open
oadp-rebasebot-app[bot] wants to merge 54 commits into
migtools:oadp-devfrom
oadp-rebasebot:rebase-bot-oadp-dev
Open

Merge https://github.com/filebrowser/filebrowser:master (be23ab3) into oadp-dev#18
oadp-rebasebot-app[bot] wants to merge 54 commits into
migtools:oadp-devfrom
oadp-rebasebot:rebase-bot-oadp-dev

Conversation

@oadp-rebasebot-app

Copy link
Copy Markdown

No description provided.

@openshift-ci openshift-ci Bot requested review from Joeavaikath and weshayutin May 18, 2026 01:10
@openshift-ci

openshift-ci Bot commented May 18, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: oadp-rebasebot-app[bot]
Once this PR has been reviewed and has the lgtm label, please assign kaovilai for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented May 18, 2026

Copy link
Copy Markdown

Hi @oadp-rebasebot-app[bot]. Thanks for your PR.

I'm waiting for a migtools member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@oadp-rebasebot-app oadp-rebasebot-app Bot changed the title Merge https://github.com/filebrowser/filebrowser:master (22b848f) into oadp-dev Merge https://github.com/filebrowser/filebrowser:master (ca0108f) into oadp-dev May 25, 2026
hacdias and others added 13 commits June 3, 2026 09:59
…, symlink escape)

- http/raw.go: strip Windows backslash separators from archive entry names
  on any host. filepath.ToSlash is a no-op for "\" on Linux, so a stored
  backslash filename was emitted verbatim and could escape the extraction
  directory on Windows extractors (zip-slip). (GHSA-gxjx-7m74-hcq8)

- http/auth.go: cap the login and signup request bodies with
  http.MaxBytesReader (1 MiB). The JSON decoder previously read an
  arbitrarily large password into memory before bcrypt truncated it,
  enabling unauthenticated memory-exhaustion DoS. (GHSA-w5fm-68j4-fpc4)

- files/file.go, http/resource.go: add files.WithinScope and refuse to
  follow a symlink whose on-disk target escapes the user's scoped root,
  on both the read path (stat) and the write path (writeFile). Prevents a
  scoped user from reading/overwriting/sharing files outside their scope
  via a pre-existing escaping symlink. (GHSA-239w-m3h6-ch8v)

Co-Authored-By: Claude Opus 4.8 <[email protected]>
@oadp-rebasebot-app oadp-rebasebot-app Bot changed the title Merge https://github.com/filebrowser/filebrowser:master (ca0108f) into oadp-dev Merge https://github.com/filebrowser/filebrowser:master (dfe6e5b) into oadp-dev Jun 8, 2026
yfzhou0904 and others added 11 commits June 13, 2026 07:17
New config option:
  --branding.disableUserProfile

This option allows to disable User Profile together
with User settings.

Signed-off-by: Michal Pryc <[email protected]>
New config option:
  --branding.defaultLoginUser "username"

This option allows to provide default Username, which will result
in hiding username field from the welcome page.

Signed-off-by: Michal Pryc <[email protected]>
Removes Help options "Delete" and "Rename" if the
following permissions are revoked from a particular
user:

  --perm.delete=false
  --perm.rename=false

Signed-off-by: Michal Pryc <[email protected]>
Add multi-stage Containerfile for UBI-based builds.

Signed-off-by: Michal Pryc <[email protected]>
Adds OWNERS file.

Signed-off-by: Michal Pryc <[email protected]>
Fix downstream changes to match upstream refactored functions.

Signed-off-by: Michal Pryc <[email protected]>
Disable Validate Title check (semantic commit PR titles are
not used downstream). Fix Go version to 1.25 and add oadp-*
branches to CI triggers.
@oadp-rebasebot-app oadp-rebasebot-app Bot changed the title Merge https://github.com/filebrowser/filebrowser:master (dfe6e5b) into oadp-dev Merge https://github.com/filebrowser/filebrowser:master (be23ab3) into oadp-dev Jun 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants