docs: clarify file_server hide case-sensitivity
details
- Finding IDs
- F-CADDY-FILESERVER-HIDE-CASE-001
- Status
- merged
- Reported date
- Rationale
- documents that hide comparisons are case-sensitive; on case-insensitive filesystems, differently-cased request paths may still resolve to the same on-disk path, so hide should not be treated as a security boundary for sensitive paths.
- PR opened by
- @1seal
- PR state observed
- closed; GitHub merged: true; 2026-09-24
- PR observation basis
- Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
- Contribution boundary
- @1seal opened this PR; this alone does not establish sole code authorship.
F-CADDY-FILESERVER-HIDE-CASE-001: Access control. The documented hide-rule boundary depends on filesystem case behavior. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-CADDY-FILESERVER-HIDE-CASE-001
Security area (1seal assessment): Authorization. The documented hide-rule boundary depends on filesystem case behavior. Reviewed 24 Sep 2026.