Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Excluding anything that starts with a period also doesn't work - RFC 5785 specs the folder .well-known with special meaning.


True, but you can whitelist /.well-known/. I don't think anything else uses dot-filenames in URLs, because not all operating systems and software even allow such file names (for instance, the file browser in Windows forbids it when creating a new file or folder).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: