Fix shared upload permissions for capability-restricted LTX backend
This commit is contained in:
@@ -27,6 +27,10 @@ outputs are mounted read-only. Only configured input/output roots are readable;
|
||||
traversal and symlinks escaping those roots are rejected. ffmpeg/ffprobe create
|
||||
thumbnails, dimensions and extracted frames on CPU; they are not inference runtimes.
|
||||
Network protocols are disabled for media inspection. HTTP Range supports seeking.
|
||||
Uploads, copied assets and thumbnails are mode 0640. Provision the writable input
|
||||
folder with a shared backend group and mode 2750 (setgid), so new files inherit
|
||||
that group. Both service identities must be able to traverse/read the shared
|
||||
folder; a root UID with dropped capabilities cannot bypass ordinary permissions.
|
||||
|
||||
Projects: initial preview retains the upstream browser-local project storage.
|
||||
Projects are specific to this browser/origin, not multiuser or cross-device synced.
|
||||
|
||||
Reference in New Issue
Block a user