Hmmmm
http://localhost:8888/..../..../..../..../..../..../.../.......
Hmmmm
http://localhost:8888/..../..../..../..../..../..../.../.......
Was gonna write:
http://localhost:8888/..../..../..../..../..../..../etc/host...
mypc
These regex substitutions are so easy to bypass :)
Of course, if you're trying to go superminimal anyway, it's not that big a deal to create a server that doesn't even have sensitive data on it. You can make init simply mount a root filesystem that only has busybox and whatever files you want to serve and starts up the httpd process and nothing else. Turn Linux into a unikernel basically. If you compile busybox yourself, you're also able to remove all the subcommands you don't actually need.
> gsub(/\/\.\.+\/?/, "/", request_filename) # avoid directory traversal
source: am "regex expert" >..< (and know how to spell)