mirror of
https://github.com/iio612/immich-native.git
synced 2026-04-15 19:21:05 +00:00
Apply umask 077 to improve security
Group and others permissions will be unset. Signed-off-by: Juhyung Park <qkrwngud825@gmail.com>
This commit is contained in:
@@ -7,6 +7,7 @@ User=immich
|
||||
Group=immich
|
||||
Type=simple
|
||||
Restart=on-failure
|
||||
UMask=0077
|
||||
|
||||
WorkingDirectory=/var/lib/immich/app
|
||||
EnvironmentFile=/var/lib/immich/env
|
||||
|
||||
@@ -9,6 +9,7 @@ User=immich
|
||||
Group=immich
|
||||
Type=simple
|
||||
Restart=on-failure
|
||||
UMask=0077
|
||||
|
||||
WorkingDirectory=/var/lib/immich/app
|
||||
EnvironmentFile=/var/lib/immich/env
|
||||
|
||||
@@ -11,6 +11,7 @@ User=immich
|
||||
Group=immich
|
||||
Type=simple
|
||||
Restart=on-failure
|
||||
UMask=0077
|
||||
|
||||
WorkingDirectory=/var/lib/immich/app
|
||||
EnvironmentFile=/var/lib/immich/env
|
||||
|
||||
@@ -29,6 +29,7 @@ if [[ "$USER" != "immich" ]]; then
|
||||
fi
|
||||
|
||||
BASEDIR=$(dirname "$0")
|
||||
umask 077
|
||||
|
||||
rm -rf $APP
|
||||
mkdir -p $APP
|
||||
@@ -37,6 +38,7 @@ mkdir -p $APP
|
||||
# This expects immich user's home directory to be on $IMMICH_PATH/home
|
||||
rm -rf $IMMICH_PATH/home
|
||||
mkdir -p $IMMICH_PATH/home
|
||||
echo 'umask 077' > $IMMICH_PATH/home/.bashrc
|
||||
|
||||
TMP=/tmp/immich-$(uuidgen)
|
||||
git clone https://github.com/immich-app/immich $TMP
|
||||
|
||||
Reference in New Issue
Block a user