validate page parameter to be a local filename #58
Loading…
Reference in New Issue
No description provided.
Delete Branch "alexlehm/tilde.chat:validate-page-param"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
the page parameter is taken directly as a filename, this would work to leave the local directory by doing page=../README for example. I added validation for the string.
This is not a security issue I think, but it is still better to validate.
thanks for the fix!