Security hardening and vulnerability boundaries

File access is limited to the selected shared folder. Abnormal directory input, out-of-bound paths, and system folders are not treated as valid shared content.

Security

Security: Security hardening and vulnerability boundaries

HQShare includes basic protections, but production deployments still need network, account, and folder boundaries.

Shared-folder boundary

File access is limited to the selected shared folder. Abnormal directory input, out-of-bound paths, and system folders are not treated as valid shared content.

Filename checks

Upload, create, rename, and download operations check file names. Empty names, control characters, system-reserved names, and directory separators are rejected.

Upload size and disk space

By default there is no upload size limit. Watch disk space instead; uploads go straight to the disk that holds the share folder, so make sure there is enough free space before sending large files, and use a stable LAN connection for large transfers to avoid interruptions. An administrator can set an upload size cap in the configuration if needed.

Download stability

Downloads use streaming transfer instead of loading large files into memory, which is better for delivery packages and log archives.

Accounts and sessions

Passwords are not stored in plaintext, and browser login sessions are protected. Change the initial manager password and disable unused accounts.

Deployment checklist

Use a dedicated shared folder, keep access on the LAN, fix the port, remove unused accounts, restrict delete permission, clean temporary files, and follow the latest downloads page for package access.

HQShare about window
Figure 1: Version and config path

The about window helps confirm version, config file location, and website before handover or support feedback.