From 1341b3421ff7d1c61bd4caf6379bd3174513e6fa Mon Sep 17 00:00:00 2001 From: ed Date: Sat, 3 Oct 2026 22:01:49 +0000 Subject: [PATCH] --smb now requres --hack-me-bro --- copyparty/__main__.py | 1 + copyparty/authsrv.py | 16 ++++++++++++++++ tests/util.py | 4 ++-- 3 files changed, 19 insertions(+), 2 deletions(-) diff --git a/copyparty/__main__.py b/copyparty/__main__.py index 58ab90c9b..bd166936c 100644 --- a/copyparty/__main__.py +++ b/copyparty/__main__.py @@ -1819,6 +1819,7 @@ def add_stats(ap): def add_yolo(ap): ap2 = ap.add_argument_group("yolo options") + ap2.add_argument("--hack-me-bro", action="store_true", help="allow enabling dangerously buggy protocols such as \033[33m--smb\033[0m / \033[33m--tftp\033[0m") ap2.add_argument("--allow-csrf", action="store_true", help="disable csrf protections; let other domains/sites impersonate you through cross-site requests; \033[1;31mDANGEROUS\033[0m / LAN-only") ap2.add_argument("--cookie-lax", action="store_true", help="allow cookies from other domains (if you follow a link from another website into your server, you will arrive logged-in); this reduces protection against CSRF") ap2.add_argument("--allow-svg-js", action="store_true", help="allow svg images to execute javascript; default-disabled because ~nobody wants it (volflag=allow_svg_js)") diff --git a/copyparty/authsrv.py b/copyparty/authsrv.py index 39003bd13..f817907bf 100644 --- a/copyparty/authsrv.py +++ b/copyparty/authsrv.py @@ -2984,6 +2984,22 @@ class AuthSrv(object): for name in vol.axs.uread: vol.axs.udot.add(name) + zi = 1 + zs = "; you must also enable --hack-me-bro to accept the total loss of security" + if self.args.hack_me_bro: + zi = 3 + zs = "" + + if self.args.smb: + t = "smb is enabled; this has serious security issues which will not be fixed" + self.log(t + zs, zi) + if zs: + errors = True + + if self.args.tftp: + t = "tftp is enabled; primitive protocol with primitive access-restrictions" + self.log(t, 3) + if errors: sys.exit(1) diff --git a/tests/util.py b/tests/util.py index abb60dfce..434cc91a3 100644 --- a/tests/util.py +++ b/tests/util.py @@ -148,7 +148,7 @@ class Cfg(Namespace): ex = "allow_flac allow_wav allow_svg_js chpw cookie_lax daw dav_auth dav_mac dav_rt dlni dothidden e2d e2ds e2dsa e2t e2ts e2tsr e2v e2vu e2vp early_ban ed emp exp force_js getmod grid gsel hardlink hardlink_only http_no_tcp ih ihead localtime log_badxml magic md_no_br nid nih no_acode no_athumb no_bauth no_clone no_cp no_dav no_db_ip no_del no_dirsz no_dupe no_dupe_m no_fnugg no_html no_lifetime no_logues no_mime no_mv no_pipe no_poll no_readme no_robots no_sb_md no_sb_lg no_scandir no_script no_tail no_tarcmp no_thumb no_vthumb no_u2abrt no_zip no_zls nrand nsort nw og og_no_head og_s_title ohead opds q rand re_dirsz redup_dry reflink rm_partial rmagic rss show_hist smb srch_dbg srch_excl srch_nfkc srch_icase stats ui_noacci ui_nocpla ui_noctxb ui_nolbar ui_nombar ui_nonav ui_notree ui_norepl ui_nosrvi uqe usernames vague_403 vc ver vol_nospawn vol_or_crash wo_up_readme wopi write_uplog xdev xlink xvol zipmaxu zs" ka.update(**{k: False for k in ex.split()}) - ex = "dav_inf dedup dotpart dotsrch hist_cow hook_v no_dhash no_fastboot no_fpool no_htp no_rescan no_sendfile no_ses no_snap no_up_list no_voldump wram re_dhash see_dots plain_ip" + ex = "dav_inf dedup dotpart dotsrch hack_me_bro hist_cow hook_v no_dhash no_fastboot no_fpool no_htp no_rescan no_sendfile no_ses no_snap no_up_list no_voldump wram re_dhash see_dots plain_ip" ka.update(**{k: True for k in ex.split()}) ex = "ah_cli ah_gen css_browser dbpath hist ipu js_browser js_other lf_url mime mimes no_forget no_hash no_idx nonsus_urls og_tpl og_ua ua_nodoc ua_nozip" @@ -163,7 +163,7 @@ class Cfg(Namespace): ex = "ac_convt au_vol dl_list du_iwho mcr mtab_age reg_cap s_thead s_tbody tail_tmax tail_who th_convt th_qv th_qvx ups_who ver_iwho zip_who" ka.update(**{k: 9 for k in ex.split()}) - ex = "ctl_re db_act forget_ip gauto idp_cookie idp_store k304 loris md_nhist no304 nosubtle qr_pin qr_wait re_maxage rproxy rsp_jtr rsp_slp s_wr_slp snap_wri theme themes turbo u2ow zipmaxn zipmaxs" + ex = "ctl_re db_act forget_ip gauto idp_cookie idp_store k304 loris md_nhist no304 nosubtle qr_pin qr_wait re_maxage rproxy rsp_jtr rsp_slp s_wr_slp snap_wri tftp theme themes turbo u2ow zipmaxn zipmaxs" ka.update(**{k: 0 for k in ex.split()}) ex = "ah_alg bname chdir chmod_f chpw_db csp_dl csp_ui db_xattr doctitle df epilogues exit favico fika ipa ipar html_head html_head_d html_head_s idp_login idp_logout lg_sba lg_sbf log_date log_fk md_sba md_sbf name og_desc og_site og_th og_title og_title_a og_title_v og_title_i opds_exts preadmes prologues readmes redup shr shr1 shr_site site smsg tcolor textfiles th_pregen txt_eol ufavico ufavico_h unlist up_site vc_url vname xff_src zipmaxt R RS SR"