Conversation
PR Summary by QodoAdd xlight 3.9.5 module bundle and release metadata
AI Description
Diagram
High-Level Assessment
Files changed (10)
|
Code Review by Qodo
1.
|
| AllowNoPassword:yes | ||
| VirtualPath: "/|e:\Bearsampp-development\sandbox\www\|R--L---S" |
There was a problem hiding this comment.
2. Nonportable anonymous ftp config 🐞 Bug ⛨ Security
The shipped 3.9.5 FTP configuration enables an anonymous/no-password user and sets its VirtualPath to an absolute developer machine path (e:\Bearsampp-development\...), which will typically not exist on user machines and can result in a broken FTP root (security risk increases if the server bind address is later widened beyond localhost).
Agent Prompt
### Issue description
The new `bin/xlight3.9.5` configuration ships an anonymous account with `AllowNoPassword:yes` and a hardcoded absolute VirtualPath pointing to a developer-local directory. This is non-portable and can lead to incorrect runtime behavior.
### Issue Context
The Gradle release build copies `bin/<version>/` config files into the packaged output as-is (no templating/substitution visible in this repo), so these defaults are what users receive.
### Fix Focus Areas
- bin/xlight3.9.5/ftpd.users[3-6]
- bin/xlight3.9.5/ftpd.password[1-3]
- bin/xlight3.9.5/ftpd.hosts[1-4]
- build.gradle[744-749]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
No description provided.