mirror of
https://git.proxmox.com/git/pve-manager
synced 2025-07-25 13:33:40 +00:00
![]() metadata is gained using a HEAD request. Due to the ability of this api endpoint to request files on internal networks (which would not be visible/accessible from outside) it is restricted to users with permissions `Sys.Audit` and `Sys.Modify` on `/`. Users with these permissions are able to alter node (network) config anyway, so this should not create any further security risk. Signed-off-by: Lorenz Stechauner <l.stechauner@proxmox.com> Reviewed-By: Dominik Csapak <d.csapak@proxmox.com> |
||
---|---|---|
aplinfo | ||
bin | ||
configs | ||
debian | ||
network-hooks | ||
PVE | ||
services | ||
test | ||
www | ||
.gitignore | ||
defines.mk | ||
Makefile | ||
spice-example-sh | ||
vzdump-hook-script.pl |