mirror of
https://github.com/karl0ss/homepage.git
synced 2025-04-29 12:03:41 +01:00
More path traversal fixes
This commit is contained in:
parent
8a4c808ee2
commit
c96e6703d3
@ -47,7 +47,7 @@ export default async function handler(req, res) {
|
|||||||
if (!mapping.segments.includes(key)) {
|
if (!mapping.segments.includes(key)) {
|
||||||
logger.debug("Unsupported segment: %s", key);
|
logger.debug("Unsupported segment: %s", key);
|
||||||
return res.status(403).json({ error: "Unsupported segment" });
|
return res.status(403).json({ error: "Unsupported segment" });
|
||||||
} else if (segments[key].includes("/")) {
|
} else if (segments[key].includes("/") || segments[key].includes("\\") || segments[key].includes("..")) {
|
||||||
logger.debug("Unsupported segment value: %s", segments[key]);
|
logger.debug("Unsupported segment value: %s", segments[key]);
|
||||||
return res.status(403).json({ error: "Unsupported segment value" });
|
return res.status(403).json({ error: "Unsupported segment value" });
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user