new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

platform_security/permissions

1 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Node.js Permission Model flags for file system access

Starting with Node.js v20, enable the stable Permission Model (v23.5.0+) using the `--permission` flag to restrict application privileges. Use `--allow-fs-read=/path/` to restrict file read access (prevents LFI); use `--allow-fs-write=/path/` to restrict write access. Enable with `node --permission index.js` or specify allowed paths: `node --permission --allow-fs-read=/uploads/ index.js`. Other flags: `--allow-child-process`, `--allow-worker`, `--allow-addons`, `--allow-wasi`. Symbolic links are followed even if they point outside allowed paths, potentially bypassing restrictions via relative symlinks. Errors triggered return: Error code 'ERR_ACCESS_DENIED', permission type, and resource path.

Give your agent this brain