mirror of
https://github.com/gohugoio/hugo.git
synced 2026-08-24 07:18:54 +00:00
c23d97904f
1f8ddb8a52 content: clarify resources front matter key descriptions e064ab8528 content: Add deprecation badges to module config page 727ca5563a github: Add push trigger to lint workflow 64dd5c9886 content: Fix typo c5bc6b6515 github: Fix lint workflow faec0c3a0a github: Combine linting actions into a single workflow 06112aeaf2 theme: Miscellaneous template edits 75d4902270 theme: Format templates with gotmplfmt fec2e2a67e content: Document that the language code in a file name must be lowercase 9dbd841ba6 content: Document the src attribute in the Page Resources metadata reference fd3ffef985 content: Fix "build from source" instructions for Windows af4c9cd4d7 content: Miscellaneous edits 408d8b2f0a content: Miscellaneous edits e8804afe6e content: Fix typo d98276be30 content: Updates for v0.161.0 01b1f8fa12 content: Note merge limitation for slice configuration values d2b18f0c8d content: Document page matcher usage for cascading values 45e5bd9ab3 content: Update Cloudflare Worker host/deploy guide b83726b89a content: Document fallback rendering for fenced code blocks 8f1eeb42bc content: Update reference for source code shortcode e8da56303b content: Add gotmplfmt to list of VS Code extensions 950fabbfd6 content: Update FAQ on feature availability error 6411146d24 content: Update quick start guide 38cc39fd51 content: Add Hugo Shortcodes to list of VS Code extensions 72d98b107b content: Misc updates to get validators to pass 9fb0e1ca35 Add a paragraph about sec boundaries e6abf5644f content: Improve syntax highlighting documentation c06193bd1a content: Update go-i18n package reference ce58fef945 Hugo 0.161.1 c7e0f63385 content: Fix package references 7f15fb3bf9 data: Regen docshelper 7483d53b55 Update HUGO_VERSION to 0.161.0 c4abcdb45f security: Add a bullet point about "pragmatic defaults" 3cd7492862 content: Improve explanation of mount removal in module configurations 4099f07bb9 content: Update GitHub Pages workflow example a6c9853a58 content: Fix typo e6f79a938b Update netlify.toml abda3d6659 content: Update Action versions in GitHub Pages workflow example 55dd288fa9 content: Add GitCMS to front-ends tools list 21081f6d49 content: Remove outdated new-in badges b2ec263884 content: Update version references 825e0b8ea9 One more CSS var adjustment 85f95a899b Adjust css.Build var docs a little df48288002 content: Updates for v0.160.0 a82a9b9797 Update HUGO_VERSION to 0.160.0 1155747dc4 content: Improve CSS processing feature description f6ce893974 content: Add css.Build to features 67b8ed1198 content: Fix typos 0f62a67863 content: Fix typo dbb42aed4a content: Document the deploy edition 549f30f933 content: De-emphasize references to the extended edition 8f5c9782d4 content: Add Pages CMS to front-ends documentation b2bfc3af48 Update HUGO_VERSION to 0.159.2 3793156fc5 content: Fix typos bacd4824ef content: Specify function namespace in example 7f2dc0d40a Regen docs.yml 65a851f731 Update HUGO_VERSION to 0.159.1 ce05fe3fc0 content: Adjust variable references in build script examples 8a04f9fe64 content: Improve hosting build script examples 67962ce05c content: Link to Codeberg Pages 404 handling fd248f57ed content: Identify esbuild as the foundation for build functions 62f02879fd content: Remove outdated content 553c407f9e content: Miscellaneous corrections 77e2cad088 content: Add new-in badge for usePackageJSON 0746e1e621 Add a page on using npm dependencies in Hugo Modules 8824850f5c Update HUGO_VERSION to 0.159.0 git-subtree-dir: docs git-subtree-split: 1f8ddb8a5230518f07c50b4b03cba3cae21081c4
90 lines
4.0 KiB
Markdown
90 lines
4.0 KiB
Markdown
---
|
|
title: Configure security
|
|
linkTitle: Security
|
|
description: Configure security.
|
|
categories: []
|
|
keywords: []
|
|
---
|
|
|
|
Hugo's built-in security policy, which restricts access to `os/exec`, remote communication, and similar operations, is configured via allowlists. By default, access is restricted. If a build attempts to use a feature not included in the allowlist, it will fail, providing a detailed message.
|
|
|
|
This is the default security configuration:
|
|
|
|
{{< code-toggle config=security />}}
|
|
|
|
enableInlineShortcodes
|
|
: (`bool`) Whether to enable [inline shortcodes]. Default is `false`.
|
|
|
|
exec.allow
|
|
: (`[]string`) A slice of [regular expressions](g) matching the names of external executables that Hugo is allowed to run.
|
|
|
|
exec.osEnv
|
|
: (`[]string`) A slice of [regular expressions](g) matching the names of operating system environment variables that Hugo is allowed to access.
|
|
|
|
funcs.getenv
|
|
: (`[]string`) A slice of [regular expressions](g) matching the names of operating system environment variables that Hugo is allowed to access with the [`os.Getenv`] function.
|
|
|
|
http.methods
|
|
: (`[]string`) A slice of [regular expressions](g) matching the HTTP methods that the [`resources.GetRemote`] function is allowed to use.
|
|
|
|
http.mediaTypes
|
|
: (`[]string`) Applicable to the `resources.GetRemote` function, a slice of [regular expressions](g) matching the `Content-Type` in HTTP responses that Hugo trusts, bypassing file content analysis for media type detection.
|
|
|
|
http.urls
|
|
: (`[]string`) A slice of [regular expressions](g) matching the URLs that the `resources.GetRemote` function is allowed to access.
|
|
|
|
node.permissions.disable
|
|
: {{< new-in 0.161.0 />}}
|
|
: (`bool`) Whether to disable the Node.js [permission model]. When `false`, Hugo runs Node.js tools with the `--permission` flag, restricting their file system and resource access to what is explicitly allowed below. Default is `false`.
|
|
|
|
node.permissions.allowAddons
|
|
: {{< new-in 0.161.0 />}}
|
|
: (`[]string`) A slice of Node.js tool names permitted to load native addons (`--allow-addons`).
|
|
|
|
node.permissions.allowChildProcess
|
|
: {{< new-in 0.161.0 />}}
|
|
: (`[]string`) A slice of Node.js tool names permitted to spawn child processes (`--allow-child-process`).
|
|
|
|
node.permissions.allowRead
|
|
: {{< new-in 0.161.0 />}}
|
|
: (`[]string`) A slice of file system paths that Node.js tools are allowed to read (`--allow-fs-read`). Paths are relative to the working directory; `"."` means the working directory itself. Use `"*"` to allow all paths.
|
|
|
|
node.permissions.allowWorker
|
|
: {{< new-in 0.161.0 />}}
|
|
: (`[]string`) A slice of Node.js tool names permitted to spawn worker threads (`--allow-worker`).
|
|
|
|
node.permissions.allowWrite
|
|
: {{< new-in 0.161.0 />}}
|
|
: (`[]string`) A slice of file system paths that Node.js tools are allowed to write (`--allow-fs-write`). Paths are relative to the working directory; `"."` means the working directory itself. Use `"*"` to allow all paths.
|
|
|
|
## Negation rules
|
|
|
|
{{< new-in 0.161.0 />}}
|
|
|
|
Any pattern in an allowlist can be negated by prefixing it with an exclamation mark (`!`) and one space to turn it into a deny rule. Deny rules take precedence over allow rules. An allowlist composed entirely of deny rules implicitly allows everything it does not deny. An empty allowlist rejects everything.
|
|
|
|
For example, to allow all URLs except those pointing to `evil.example.com`:
|
|
|
|
```toml
|
|
[security.http]
|
|
urls = ['.*', '! ^https?://evil\.example\.com']
|
|
```
|
|
|
|
Setting an allowlist to the string `none` will completely disable the associated feature.
|
|
|
|
## Environment variables
|
|
|
|
You can also override your project configuration with environment variables. For example, to block `resources.GetRemote` from accessing any URL:
|
|
|
|
```txt
|
|
export HUGO_SECURITY_HTTP_URLS=none
|
|
```
|
|
|
|
Learn more about [using environment variables] to configure your site.
|
|
|
|
[`os.Getenv`]: /functions/os/getenv
|
|
[`resources.GetRemote`]: /functions/resources/getremote
|
|
[inline shortcodes]: /content-management/shortcodes/#inline
|
|
[permission model]: https://nodejs.org/api/permissions.html#permission-model
|
|
[using environment variables]: /configuration/introduction/#environment-variables
|