hugo/resources
Bjørn Erik Pedersen f4389e48ce
Add some basic security policies with sensible defaults
This ommmit contains some security hardening measures for the Hugo build runtime.

There are some rarely used features in Hugo that would be good to have disabled by default. One example would be the "external helpers".

For `asciidoctor` and some others we use Go's `os/exec` package to start a new process.

These are a predefined set of binary names, all loaded from `PATH` and with a predefined set of arguments. Still, if you don't use `asciidoctor` in your project, you might as well have it turned off.

You can configure your own in the new `security` configuration section, but the defaults are configured to create a minimal amount of site breakage. And if that do happen, you will get clear instructions in the loa about what to do.

The default configuration is listed below. Note that almost all of these options are regular expression _whitelists_ (a string or a slice); the value `none` will block all.

```toml
[security]
  enableInlineShortcodes = false
  [security.exec]
    allow = ['^dart-sass-embedded$', '^go$', '^npx$', '^postcss$']
    osEnv = ['(?i)^(PATH|PATHEXT|APPDATA|TMP|TEMP|TERM)$']

  [security.funcs]
    getenv = ['^HUGO_']

  [security.http]
    methods = ['(?i)GET|POST']
    urls = ['.*']
```
2021-12-16 09:40:22 +01:00
..
images Improve handling of remote image/jpeg resources (#9278) 2021-12-13 08:55:15 +01:00
internal all: Format code with gofumpt 2020-12-03 13:12:58 +01:00
jsconfig all: Format code with gofumpt 2020-12-03 13:12:58 +01:00
page Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
postpub Prevent minifier from removing quoutes around post-processed attributes 2021-08-22 12:47:47 +02:00
resource Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
resource_factories Add some basic security policies with sensible defaults 2021-12-16 09:40:22 +01:00
resource_transformers Add some basic security policies with sensible defaults 2021-12-16 09:40:22 +01:00
testdata Add custom font support to images.Text 2021-12-07 16:53:02 +01:00
errorResource.go Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
image.go hugofs: Make FileMeta a struct 2021-07-15 17:14:26 +02:00
image_cache.go hugofs: Make FileMeta a struct 2021-07-15 17:14:26 +02:00
image_extended_test.go resources: Regenerate image golden testdata 2021-07-07 17:25:14 +02:00
image_test.go Add custom font support to images.Text 2021-12-07 16:53:02 +01:00
post_publish.go Add basic "post resource publish support" 2020-04-07 21:59:20 +02:00
resource.go Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
resource_cache.go all: Format code with gofumpt 2020-12-03 13:12:58 +01:00
resource_cache_test.go Improve the server assets cache invalidation logic 2019-08-13 18:09:46 +02:00
resource_metadata.go Misc config loading fixes 2021-06-14 17:00:32 +02:00
resource_metadata_test.go all: Format code with gofumpt 2020-12-03 13:12:58 +01:00
resource_spec.go Add some basic security policies with sensible defaults 2021-12-16 09:40:22 +01:00
resource_test.go resources: Use default math/rand.Source for concurrency safety 2021-09-19 12:18:30 +02:00
testhelpers_test.go Add some basic security policies with sensible defaults 2021-12-16 09:40:22 +01:00
transform.go Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
transform_test.go resources: Regenerate image golden testdata 2021-07-07 17:25:14 +02:00