4 مستودعات
Configurations that define granular permissions for system resources based on file and registry paths.
Distinct from Access Rules: Distinct from general access rules: focuses on path-specific filtering for sandboxed environments.
Explore 4 awesome GitHub repositories matching software engineering & architecture · Path-Based. Refine with filters or upvote what's useful.
Sandboxie is an operating system-level virtualization tool designed to run Windows applications in isolated, secure environments. By intercepting system calls and redirecting file system and registry modifications to a separate, discardable storage area, it prevents untrusted software from making permanent changes to the host system. This containment ensures that browser history, temporary files, and potential malware remain trapped within the sandbox, protecting the integrity and privacy of the underlying host. The software distinguishes itself through granular control over the isolation env
Enforces granular security policies by evaluating every file, registry, and network request against a defined set of access rules.
This project is a version control documentation tool designed to automate the generation of release notes and changelogs. It functions as a pipeline-based engine that parses repository history, categorizes commits, and transforms them into structured documentation. By leveraging conventional commit patterns or custom regular expressions, it provides a consistent method for tracking project evolution and managing semantic versioning. What distinguishes this tool is its highly flexible template-driven architecture, which allows for deep customization of output formatting, grouping, and sorting.
Generates documentation for specific subdirectories by focusing analysis on relevant file paths.
FileBrowser is an open-source, self-hosted file management interface that runs as a single binary with no external dependencies. It provides a web-based interface for browsing, uploading, editing, and sharing files on a remote server, with a core architecture built on JWT-based stateless authentication and a rule-based path permission engine that controls access at the directory level. The project distinguishes itself through a comprehensive access control system that supports multi-provider authentication including OIDC, LDAP, external JWT, and two-factor authentication, alongside granular p
Evaluates ordered allow/deny rules against user identity and group membership to control access at the directory level.
تعمل هذه الأداة كخادم لبروتوكول سياق النموذج (Model Context Protocol) الذي يربط نماذج الذكاء الاصطناعي ببيئات التطوير المحلية. فهي تمكن مساعدي الذكاء الاصطناعي من إجراء تحليل لقاعدة الكود، وتنفيذ أدوات سطر الأوامر، وتطبيق تعديلات برمجية مؤتمتة مباشرة على ملفات المشروع المحلية. ومن خلال التكامل مع Gemini API، يسهل النظام التفاعل العميق بين النماذج الخارجية وموارد النظام المحلي. يتميز المشروع بإطار عمل قوي للأمان والموثوقية مصمم لسير عمل التطوير المؤتمت. فهو يفرض ضوابط وصول صارمة تعتمد على المسارات لحماية الملفات الحساسة، ويستخدم بيئات معزولة (sandbox) لتنفيذ الكود المولد. ولضمان التشغيل المستمر، تطبق الأداة توجيهاً ديناميكياً للنماذج (fallback routing)، والذي يقوم بالتبديل تلقائياً بين مستويات النماذج إذا تم الوصول إلى حدود الاستخدام، كما يستخدم تقييم نموذج ثانوي للتحقق من جودة المخرجات المولدة. يدعم النظام مجموعة واسعة من العمليات التقنية، بما في ذلك استخراج البيانات المهيكلة من مخرجات الطرفية، وإدارة سجل المحادثات، وتهيئة معلمات التنفيذ للمهام طويلة الأمد. كما يوفر قدرات شاملة لمسح أدلة المشروع، وتوليد رؤى تقنية، وإدارة نوافذ السياق للتعامل مع التوثيق المكثف ومعلومات قاعدة الكود.
Enforces strict filesystem access controls by validating requested file paths against defined allowlists before granting permissions.