Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Apply file transfer restrictions to the integrated browser

未关闭
#7,884 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
48/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
冷清
技术栈
typescript, vscode
领域
devtools, security

调研方向

首先定位 code-server 界面中现有的文件传输限制处理逻辑和集成浏览器入口点。跟踪浏览器上传和下载如何到达本地客户端与远程服务器,然后验证跨越该边界的传输会被阻止,而仅在服务器上执行的操作仍然允许进行。

由索引模型根据 Issue 内容生成。

描述

code-server Improvement

What is your suggestion?

I would like code-server to apply the same file transfer restrictions to the integrated browser available directly inside the VS Code/code-server interface.

Today, code-server can restrict actions such as drag-and-drop, file download, and file upload between the user's local machine and the remote code-server environment. However, the integrated browser inside the interface should also respect these restrictions.

If file transfer is disabled, the integrated browser should not allow users to bypass the restriction by downloading files to their local machine or uploading files from their local machine.

However, the browser should still be allowed to download or upload files only within the remote server environment. For example:

  • downloading a file from a website should be allowed only if the destination is a folder on the remote server;
  • uploading a file should be allowed only if the file comes from the remote server filesystem;
  • uploading or downloading directly between the integrated browser and the local client machine should remain blocked when file transfer restrictions are enabled.

In short, the restriction should prevent transfers outside of the server, but should still allow file operations that stay entirely inside the server environment.

Why do you want this feature?

This would improve security and make file transfer restrictions consistent across the whole code-server interface.

In managed or restricted environments, administrators may disable drag-and-drop, file downloads, and file uploads to prevent data from being moved between the remote server and the local user device.

If the integrated browser can still upload files from the local machine or download files to the local machine, users may be able to bypass these restrictions. This weakens the security model and makes the existing restrictions less effective.

The expected behavior would be:

  • local machine to server transfer: blocked when upload is disabled;
  • server to local machine transfer: blocked when download is disabled;
  • server-only file operations through the integrated browser: allowed.

This would be useful for enterprise, education, sandbox, and controlled development environments where administrators need strong control over data movement.

Are there any workarounds to get this functionality today?

There does not seem to be a clean native workaround today.

Possible workarounds may include disabling the integrated browser entirely, using proxy or network-level restrictions, or maintaining custom patches, but these approaches are not ideal. They can be difficult to maintain, may break legitimate workflows, and do not provide a clear policy-based way to enforce the same restrictions everywhere in code-server.

A native option would be much better because it would make the behavior predictable and consistent with the existing file transfer restrictions.

Are you interested in submitting a PR for this?

Not at the moment, but I would be happy to provide more details, test the behavior, or validate a proposed implementation in a restricted code-server environment.

主要语言
TypeScript
星标
79.4k
派生
6.9k
平均合并
2 天 13 小时
30 天内合并 PR
39

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

coder/code-server 的其他 Issue

查看 coder/code-server 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。