[0] https://github.com/eliben/static-server/blob/3ce83524ed54298...
[0] https://github.com/eliben/static-server/blob/3ce83524ed54298...
While true, I don't think the author should refrain from making code available based on the potential negatives from others using code they didn't even bother to read the documentation for.
Need I be called out, now?
The shutdown endpoint is used for robust testing; I suppose I can hide it a bit more, like using an environment variable or something.
Mainly because of the shutdown endpoint, but also that the -cors flag returns "Access-Control-Allow-Origin: *" exposing you to arbitrary cross origin requests.
$ npm install http-server
$ http-server .
$ go run github.com/eliben/static-server@latest
I have this seen also in automotive. "This is no problem, because this is not connected to the Internet." Then a few years later you have a DefCon presentation "GM hack, you can control the whole car via the Internet".