On Unix-based systems, ports below 1024 are seen as "system ports", and cannot be bound to unless by root. This is a security risk for an FTP server that listens on control port 21. Service management can allow us to bind to system ports without an elevated user but we should handle dropping into a defined user in case the server is ran as a superuser.
We can most likely implement this drop when we initialize a client, as that is where file manipulations are handled. The main thread simply handles incoming connections and distributes them, which isn't a big security risk under root.
User/group should be handled by configuration values, defaulting to "ftp".
On Unix-based systems, ports below 1024 are seen as "system ports", and cannot be bound to unless by root. This is a security risk for an FTP server that listens on control port 21. Service management can allow us to bind to system ports without an elevated user but we should handle dropping into a defined user in case the server is ran as a superuser.
We can most likely implement this drop when we initialize a client, as that is where file manipulations are handled. The main thread simply handles incoming connections and distributes them, which isn't a big security risk under root.
User/group should be handled by configuration values, defaulting to "ftp".
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
On Unix-based systems, ports below 1024 are seen as "system ports", and cannot be bound to unless by root. This is a security risk for an FTP server that listens on control port 21. Service management can allow us to bind to system ports without an elevated user but we should handle dropping into a defined user in case the server is ran as a superuser.
We can most likely implement this drop when we initialize a client, as that is where file manipulations are handled. The main thread simply handles incoming connections and distributes them, which isn't a big security risk under root.
User/group should be handled by configuration values, defaulting to "ftp".