Skip to content

Conversation

@perber
Copy link
Owner

@perber perber commented Feb 11, 2026

…abled

Copilot AI review requested due to automatic review settings February 11, 2026 16:53
@perber perber linked an issue Feb 11, 2026 that may be closed by this pull request
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adjusts the Gin router configuration so that /assets is no longer always publicly served, aligning asset download access with the instance’s PublicAccess / AuthDisabled settings.

Changes:

  • Conditionally serves /assets publicly only when PublicAccess or AuthDisabled is enabled; otherwise serves /assets behind RequireAuth.
  • Disables directory listing for the assets filesystem.
  • Minor whitespace-only formatting cleanups in the /branding/:filename handler.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Copy link
Contributor

Copilot AI commented Feb 11, 2026

@perber I've opened a new pull request, #679, to work on those changes. Once the pull request is ready, I'll request review from you.

@perber perber merged commit a70419e into main Feb 11, 2026
4 of 5 checks passed
@perber perber deleted the fix/assets-are-public-accessible branch February 11, 2026 17:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

/assets/ is publicly accessible when when public access is disabled

2 participants