mirror of
				https://github.com/karl0ss/homepage.git
				synced 2025-11-04 08:20:58 +00:00 
			
		
		
		
	More path traversal fixes
This commit is contained in:
		
							parent
							
								
									8a4c808ee2
								
							
						
					
					
						commit
						c96e6703d3
					
				@ -47,7 +47,7 @@ export default async function handler(req, res) {
 | 
			
		||||
            if (!mapping.segments.includes(key)) {
 | 
			
		||||
              logger.debug("Unsupported segment: %s", key);
 | 
			
		||||
              return res.status(403).json({ error: "Unsupported segment" });
 | 
			
		||||
            } else if (segments[key].includes("/")) {
 | 
			
		||||
            } else if (segments[key].includes("/") || segments[key].includes("\\") || segments[key].includes("..")) {
 | 
			
		||||
              logger.debug("Unsupported segment value: %s", segments[key]);
 | 
			
		||||
              return res.status(403).json({ error: "Unsupported segment value" });
 | 
			
		||||
            }
 | 
			
		||||
 | 
			
		||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user