]> git.maquefel.me Git - brevno-suite/hugo/commitdiff
Merge commit '336622d5e7afd9334cd2de7150d4f16bdf7c24f9'
authorBjørn Erik Pedersen <bjorn.erik.pedersen@gmail.com>
Wed, 1 Mar 2023 10:56:07 +0000 (11:56 +0100)
committerBjørn Erik Pedersen <bjorn.erik.pedersen@gmail.com>
Wed, 1 Mar 2023 10:56:07 +0000 (11:56 +0100)
1  2 
docs/content/en/about/security-model/index.md
docs/content/en/getting-started/quick-start.md
docs/layouts/_default/_markup/render-codeblock-mermaid.html
docs/layouts/partials/hooks/before-body-end.html

index 66cb15463311ce9ef3c62af3b9541a34d4a708f3,0000000000000000000000000000000000000000..d4dacd9bf2e72e1bd031e2860f99f05eb9f44d9b
mode 100644,000000..100644
--- /dev/null
@@@ -1,65 -1,0 +1,65 @@@
- Templates authors (you) are trusted, but the data you send in is not.
 +---
 +title: Hugo's Security Model
 +description: A summary of Hugo's security model.
 +date: 2019-10-01
 +layout: single
 +keywords: ["Security", "Privacy"]
 +menu:
 +  docs:
 +    parent: "about"
 +    weight: 4
 +weight: 5
 +sections_weight: 5
 +aliases: [/security/]
 +toc: true
 +---
 +
 +## Runtime Security
 +
 +Hugo produces static output, so once built, the runtime is the browser (assuming the output is HTML) and any server (API) that you integrate with.
 +
 +But when developing and building your site, the runtime is the `hugo` executable. Securing a runtime can be [a real challenge](https://blog.logrocket.com/how-to-protect-your-node-js-applications-from-malicious-dependencies-5f2e60ea08f9/).
 +
 +**Hugo's main approach is that of sandboxing and a security policy with strict defaults:**
 +
 +* Hugo has a virtual file system and only the main project (not third-party components) is allowed to mount directories or files outside the project root.
 +* Only the main project can walk symbolic links.
 +* User-defined components have read-only access to the filesystem.
 +* We shell out to some external binaries to support [Asciidoctor](/content-management/formats/#list-of-content-formats) and similar, but those binaries and their flags are predefined and disabled by default (see [Security Policy](#security-policy)). General functions to run arbitrary external OS commands have been [discussed](https://github.com/gohugoio/hugo/issues/796), but not implemented because of security concerns.
 +
 +## Security Policy
 +
 +Hugo has a built-in security policy that restricts access to [os/exec](https://pkg.go.dev/os/exec), remote communication and similar.
 +
 +The default configuration is listed below. Any build using features not in the allow list of the security policy will fail with a detailed message about what needs to be done. Most of these settings are allow lists (string or slice, [Regular Expressions](https://pkg.go.dev/regexp) or `none` which matches nothing).
 +
 +{{< code-toggle config="security" />}}
 +
 +Note that these and other config settings in Hugo can be overridden by the OS environment. If you want to block all remote HTTP fetching of data:
 +
 +```txt
 +HUGO_SECURITY_HTTP_URLS=none hugo
 +```
 +
 +## Dependency Security
 +
 +Hugo is built as a static binary using [Go Modules](https://github.com/golang/go/wiki/Modules) to manage its dependencies. Go Modules have several safeguards, one of them being the `go.sum` file. This is a database of the expected cryptographic checksums of all of your dependencies, including transitive dependencies.
 +
 +[Hugo Modules](/hugo-modules/) is a feature built on top of the functionality of Go Modules. Like Go Modules, a Hugo project using Hugo Modules will have a `go.sum` file. We recommend that you commit this file to your version control system. The Hugo build will fail if there is a checksum mismatch, which would be an indication of [dependency tampering](https://julienrenaux.fr/2019/12/20/github-actions-security-risk/).
 +
 +## Web Application Security
 +
 +These are the security threats as defined by [OWASP](https://en.wikipedia.org/wiki/OWASP).
 +
 +For HTML output, this is the core security model:
 +
 +<https://pkg.go.dev/html/template#hdr-Security_Model>
 +
 +In short:
 +
++Template and configuration authors (you) are trusted, but the data you send in is not.
 +This is why you sometimes need to use the _safe_ functions, such as `safeHTML`, to avoid escaping of data you know is safe.
 +There is one exception to the above, as noted in the documentation: If you enable inline shortcodes, you also say that the shortcodes and data handling in content files are trusted, as those macros are treated as pure text.
 +It may be worth adding that Hugo is a static site generator with no concept of dynamic user input.
 +
 +For content, the default Markdown renderer is [configured](/getting-started/configuration-markup) to remove or escape potentially unsafe content. This behavior can be reconfigured if you trust your content.
index 824d6030aabc629d5cd47739215b1eec56e8a22b,0000000000000000000000000000000000000000..d49997570a28573fb2edc30e63f4938419472bf8
mode 100644,000000..100644
--- /dev/null
@@@ -1,219 -1,0 +1,225 @@@
- If you are a Windows user, you must run these commands with [PowerShell]. You cannot use Windows Powershell, which is a different application, or the Command Prompt. You may also use a Linux shell if available.
 +---
 +title: Quick Start
 +linktitle: Quick Start
 +description: Learn to create a Hugo site in minutes.
 +categories: [getting started]
 +keywords: [quick start,usage]
 +menu:
 +  docs:
 +    parent: getting-started
 +    weight: 10
 +weight: 10
 +toc: true
 +aliases: [/quickstart/,/overview/quickstart/]
 +---
 +
 +In this tutorial you will:
 +
 +1. Create a site
 +2. Add content
 +3. Configure the site
 +4. Publish the site
 +
 +## Prerequisites
 +
 +Before you begin this tutorial you must:
 +
 +1. [Install Hugo] (the extended edition)
 +1. [Install Git]
 +
 +You must also be comfortable working from the command line.
 +
 +## Create a site
 +
 +### Commands
 +
 +{{% note %}}
++**If you are a Windows user:**
++
++- Do not use the Command Prompt
++- Do not use Windows PowerShell
++- Run these commands from [PowerShell] or a Linux terminal such as WSL or Git Bash
++
++PowerShell and Windows PowerShell are different applications.
 +
 +[PowerShell]: https://learn.microsoft.com/en-us/powershell/scripting/install/installing-powershell-on-windows
 +{{% /note %}}
 +
 +Run these commands to create a Hugo site with the [Ananke] theme. The next section provides an explanation of each command.
 +
 +```text
 +hugo new site quickstart
 +cd quickstart
 +git init
 +git submodule add https://github.com/theNewDynamic/gohugo-theme-ananke themes/ananke
 +echo "theme = 'ananke'" >> config.toml
 +hugo server
 +```
 +
 +View your site at the URL displayed in your terminal. Press `Ctrl + C` to stop Hugo's development server.
 +
 +### Explanation of commands
 +
 +Create the [directory structure] for your project in the `quickstart` directory.
 +
 +```text
 +hugo new site quickstart
 +```
 +
 +Change the current directory to the root of your project.
 +
 +```text
 +cd quickstart
 +```
 +
 +Initialize an empty Git repository in the current directory.
 +
 +```text
 +git init
 +```
 +
 +Clone the [Ananke] theme into the `themes` directory, adding it to your project as a [Git submodule].
 +
 +```text
 +git submodule add https://github.com/theNewDynamic/gohugo-theme-ananke themes/ananke
 +```
 +
 +Append a line to the site configuration file, indicating the current theme.
 +
 +```text
 +echo "theme = 'ananke'" >> config.toml
 +```
 +
 +Start Hugo's development server to view the site.
 +
 +```text
 +hugo server
 +```
 +
 +Press `Ctrl + C` to stop Hugo's development server.
 +
 +## Add content
 +
 +Add a new page to your site.
 +
 +```text
 +hugo new posts/my-first-post.md
 +```
 +
 +Hugo created the file in the `content/posts` directory. Open the file with your editor.
 +
 +```text
 +---
 +title: "My First Post"
 +date: 2022-11-20T09:03:20-08:00
 +draft: true
 +---
 +```
 +
 +Notice the `draft` value in the [front matter] is `true`. By default, Hugo does not publish draft content when you build the site. Learn more about [draft, future, and expired content].
 +
 +Add some [markdown] to the body of the post, but do not change the `draft` value.
 +
 +[markdown]: https://commonmark.org/help/
 +
 +```text
 +---
 +title: "My First Post"
 +date: 2022-11-20T09:03:20-08:00
 +draft: true
 +---
 +## Introduction
 +
 +This is **bold** text, and this is *emphasized* text.
 +
 +Visit the [Hugo](https://gohugo.io) website!
 +```
 +
 +Save the file, then start Hugo’s development server to view the site. You can run either of the following commands to include draft content.
 +
 +```text
 +hugo server --buildDrafts
 +hugo server -D
 +```
 +
 +View your site at the URL displayed in your terminal. Keep the development server running as you continue to add and change content.
 +
 +{{% note %}}
 +Hugo's rendering engine conforms to the CommonMark [specification] for markdown. The CommonMark organization provides a useful [live testing tool] powered by the reference implementation.
 +
 +[live testing tool]: https://spec.commonmark.org/dingus/
 +[specification]: https://spec.commonmark.org/
 +{{% /note %}}
 +
 +## Configure the site
 +
 +With your editor, open the [site configuration] file (`config.toml`) in the root of your project.
 +
 +```text
 +baseURL = 'http://example.org/'
 +languageCode = 'en-us'
 +title = 'My New Hugo Site'
 +theme = 'ananke'
 +```
 +
 +Make the following changes:
 +
 +1. Set the `baseURL` for your production site. This value must begin with the protocol and end with a slash, as shown above.
 +
 +2. Set the `languageCode` to your language and region.
 +
 +3. Set the `title` for your production site.
 +
 +Start Hugo's development server to see your changes, remembering to include draft content.
 +
 +```text
 +hugo server -D
 +```
 +
 +{{% note %}}
 +Most theme authors provide configuration guidelines and options. Make sure to visit your theme's repository or documentation site for details.
 +
 +[The New Dynamic], authors of the Ananke theme, provide [documentation] for configuration and usage. They also provide a [demonstration site].
 +
 +[demonstration site]: https://gohugo-ananke-theme-demo.netlify.app/
 +[documentation]: https://github.com/theNewDynamic/gohugo-theme-ananke#readme
 +[The New Dynamic]: https://www.thenewdynamic.com/
 +{{% /note %}}
 +
 +## Publish the site
 +
 +In this step you will _publish_ your site, but you will not _deploy_ it.
 +
 +When you _publish_ your site, Hugo creates the entire static site in the `public` directory in the root of your project. This includes the HTML files, and assets such as images, CSS files, and JavaScript files.
 +
 +When you publish your site, you typically do _not_ want to include [draft, future, or expired content]. The command is simple.
 +
 +```text
 +hugo
 +```
 +
 +To learn how to _deploy_ your site, see the [hosting and deployment] section.
 +
 +## Ask for help
 +
 +Hugo's [forum] is an active community of users and developers who answer questions, share knowledge, and provide examples. A quick search of over 20,000 topics will often answer your question. Please be sure to read about [requesting help] before asking your first question.
 +
 +## Other resources
 +
 +For other resources to help you learn Hugo, including books and video tutorials, see the [external learning resources](/getting-started/external-learning-resources/) page.
 +
 +[Ananke]: https://github.com/theNewDynamic/gohugo-theme-ananke
 +[directory structure]: /getting-started/directory-structure
 +[draft, future, and expired content]: /getting-started/usage/#draft-future-and-expired-content
 +[draft, future, or expired content]: /getting-started/usage/#draft-future-and-expired-content
 +[external learning resources]:/getting-started/external-learning-resources/
 +[forum]: https://discourse.gohugo.io/
 +[forum]: https://discourse.gohugo.io/
 +[front matter]: /content-management/front-matter
 +[Git submodule]: https://git-scm.com/book/en/v2/Git-Tools-Submodules
 +[hosting and deployment]: /hosting-and-deployment/
 +[Install Git]: https://git-scm.com/book/en/v2/Getting-Started-Installing-Git
 +[Install Hugo]: /installation/
 +[Requesting Help]: https://discourse.gohugo.io/t/requesting-help/9132
 +[Requesting Help]: https://discourse.gohugo.io/t/requesting-help/9132
 +[site configuration]: /getting-started/configuration/
index 59641551ca67e2fb2350a3779d09159f7675a50e,0000000000000000000000000000000000000000..94ea0cad0846ab81877849f8b595a1457bcf5adb
mode 100644,000000..100644
--- /dev/null
@@@ -1,4 -1,0 +1,4 @@@
- <div class="mermaid">
++<pre class="mermaid">
 +  {{- .Inner | safeHTML }}
- </div>
++</pre>
 +{{ .Page.Store.Set "hasMermaid" true }}
index fb7ae20bad879df1e0d04df28451f069dc979c25,0000000000000000000000000000000000000000..dab653508b46eb159361e6e89102db6f6a9c456f
mode 100644,000000..100644
--- /dev/null
@@@ -1,6 -1,0 +1,7 @@@
-   <script src="https://cdn.jsdelivr.net/npm/mermaid/dist/mermaid.min.js"></script>
-   <script>
 +{{ if .Page.Store.Get "hasMermaid" }}
++  <script type="module" async>
++    import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@9/+esm';
++    
 +    mermaid.initialize({ startOnLoad: true });
 +  </script>
 +{{ end }}