Creating a hosted subdomain gated `root_dir` on `write`, and hosting serves everything under that directory with the ACL deliberately bypassed. So a recipient of a `write` share could point a `*.puter.site` subdomain at the owner's folder and make the subtree world-readable — continuously, covering files the owner added later, with the row under the recipient's account where nothing the owner can list would show it. `update` had the same gate for a changed `root_dir`. `#checkPublishAccess` now decides both: the actor's own tree still takes `write`, anyone else's takes `manage` — "Can edit & share", the level that delegates the decision. Keyed on who owns the entry rather than asking for `manage` outright, which is what the ticket proposed. `manage`'s is-owner implicator declines to answer for app actors, so a flat `manage` would refuse every app publishing a directory its user handed it, with no way for the app to obtain the grant. The write check still runs first — it is what masks a directory the caller cannot see as a 404 — and `manage` satisfies every lower mode, so the order costs a manage-holder nothing. The GUI's Publish As Website item reuses the own-it-or-`manage` answer it already computes for sharing, so it is not offered where this would refuse. Docs state the rule on `hosting.create()` and in `share()`'s level list. Regression tests fail without the driver change: a write-share recipient is refused on create and on repointing an existing subdomain, while `manage` and the actor's own directory are accepted.
The Open-Source Internet Computer!
« LIVE DEMO »
Puter.com
·
App Store
·
Developers
·
X
Puter
Puter is an advanced, open-source, self-hostable internet computer designed to be feature-rich, fast, and highly extensible.
For Users
Puter's goal is to provide you with every app and feature you need to work, create, and play under one roof. From a simple Notepad and Voice Recorder to Spreadsheet and Camera, Puter wants to be the all-in-one solution for your digital life.
For Developers
Puter provides everything you need to build and publish web apps and games. From AI to Cloud Storage and Database to Serverless Workers, Puter has you covered. Puter also helps you get users! Once you build your app, you can publish it on our App Store to reach and monetize users.
Getting Started
💻 Local Development
git clone https://github.com/HeyPuter/puter
cd puter
npm install
npm start
→ This should launch Puter at http://puter.localhost:4100
🚀 Self-Hosting
Linux/macOS
curl -fsSL https://puter.com/selfhost | sh
Windows
irm https://puter.com/selfhost?os=windows | iex
→ For more details, see Self-Hosting Puter.
☁️ Puter.com
Puter is available as a hosted service at puter.com.
Support
Connect with the maintainers and community through these channels:
- Bug report or feature request? Please open an issue.
- X (Twitter): x.com/HeyPuter
- Security issues or abuse reports? security@puter.com
- Email maintainers at hi@puter.com
We are always happy to help you with any questions you may have. Don't hesitate to ask!
License
This repository, including all its contents, sub-projects, modules, and components, is licensed under AGPL-3.0 unless explicitly stated otherwise. Third-party libraries included in this repository may be subject to their own licenses.
Translations
- Arabic / العربية
- Armenian / Հայերեն
- Bengali / বাংলা
- Chinese / 中文
- Danish / Dansk
- English
- Farsi / فارسی
- Finnish / Suomi
- French / Français
- German / Deutsch
- Hebrew/ עברית
- Hindi / हिंदी
- Hungarian / Magyar
- Indonesian / Bahasa Indonesia
- Italian / Italiano
- Japanese / 日本語
- Korean / 한국어
- Malay / Bahasa Malaysia
- Malayalam / മലയാളം
- Dutch / Nederlands
- Polish / Polski
- Odia / ଓଡ଼ିଆ
- Portuguese / Português
- Punjabi / ਪੰਜਾਬੀ
- Romanian / Română
- Russian / Русский
- Spanish / Español
- Swedish / Svenska
- Tamil / தமிழ்
- Telugu / తెలుగు
- Thai / ไทย
- Turkish / Türkçe
- Ukrainian / Українська
- Urdu / اردو
- Vietnamese / Tiếng Việt

