aboutsummaryrefslogtreecommitdiff
path: root/TODO.md
diff options
context:
space:
mode:
authoranon2025-07-05 23:39:24 +0200
committeranon2025-07-05 23:39:24 +0200
commitbe96ef3c69aa497dd0a663de6cc3318fa7d77893 (patch)
treef49d9901f2a3603f1117946d3a85bd6e1e976fa7 /TODO.md
parent82684d6d1ca7e744af74ad8da3b9ea2708d1c468 (diff)
downloademil-up.chud.cyou-be96ef3c69aa497dd0a663de6cc3318fa7d77893.tar.xz
emil-up.chud.cyou-be96ef3c69aa497dd0a663de6cc3318fa7d77893.tar.zst
fix bug, implement overwritting, bump todo
Diffstat (limited to 'TODO.md')
-rw-r--r--TODO.md4
1 files changed, 3 insertions, 1 deletions
diff --git a/TODO.md b/TODO.md
index 90d4c51..9ae4aff 100644
--- a/TODO.md
+++ b/TODO.md
@@ -1,2 +1,4 @@
-* configurable force overwritting
* include some tmp file cleaner scripts or atleast leave recommendations
+* by spoofing the request, it might be currently possible to upload files
+to a parent dictionary; this should be tested and fixed, but should be fine
+as long as the person running the service doesnt run it as root