PlugStaticLs
Directory Index for Plug/Phoenix Static Assets
WARNING: inherent vulnerabilities regarding directory listing
Providing directory listing may reveal following vulnerabilities:
- Contents of unintended files left in the directory will be shown to the HTTP clients, including the search engines.
- Directory listing requires file stat operations and may result in consuming computing resources.
- Directory listing reveals not only the file contents but the file name, the last modification time (mtime), and the size.
Here is a list of security advisories against making directory listing available to the public:
- Mitre: CWE-548: Information Exposure Through Directory Listing
- OWASP Periodic Table of Vulnerabilities - Directory Indexing
- The Web Application Security Consortium / Directory Indexing
Do not provide directory listing unless you are 100% sure about the contents in the directory.
Installation
If available in Hex, the package can be installed as:
Add
plug_static_ls
to your list of dependencies inmix.exs
:def deps do [{:plug_static_ls, "~> 0.5.2"}] end
Ensure
plug_static_ls
is started before your application:def application do [applications: [:plug_static_ls]] end
Prerequisites
The filename locale of the Erlang VM must be explicitly specified to UTF-8.
See Erlang’s erl +fnu
option description for the details.
Note: Elixir assumes UTF-8 usage on the filenames and internal strings.
Usage
Add PlugStaticLs
after Plug.Static
in endpoint.ex
. The access restriction options for PlugStaticLs
should include the corresponding setting of Plug.Static
. Allow access only to the directories where the index is really required.
plug Plug.Static, at: "/", from: :my_app
plug PlugStaticLs, at: "/", from: :my_app, only: ~w(with_listing)
# Note: non-existent file will be routed here
# Explicit plug to catch this case is required
License
Acknowledment
The basic skeleton of this package is derived from
static.ex
aka Plug.Static
module of the Plug repository.
The directory listing page design is derived from Yaws Web Server.