Hacker News new | ask | show | jobs
by its-summertime 635 days ago
Once at a certain level of complexity, e.g. having several hundred/thousand resources, then you start automating your hardcoded paths, and then you still can get bitten.

vs just putting things in a subfolder of your repo or whatever and having the default handling not accept `..` path components

1 comments

But OP isn't reaching that certain level of complexity, doesn't have thousands of resources, he is hosting his own website.