diff options
| author | la_ninpre <aaoth@aaoth.xyz> | 2026-01-28 11:30:03 +0300 |
|---|---|---|
| committer | la_ninpre <aaoth@aaoth.xyz> | 2026-01-28 11:39:44 +0300 |
| commit | 2f0f3d45f4335327c269a689fbeb62b3003695aa (patch) | |
| tree | 4a6f455e33572e1f58beefc4a03efcaccf89408e | |
| parent | f7073bfe61c6e011ec861edd07c791c884b6ff45 (diff) | |
static files: allow files in a subdirectory
allowing '/' in paths is a bit scary, but
replacing the check with reject on '..' seems to work.
please correct me if i'm wrong and this is insecure.
| -rw-r--r-- | data.c | 2 | ||||
| -rw-r--r-- | html.c | 2 |
2 files changed, 2 insertions, 2 deletions
@@ -2691,7 +2691,7 @@ static int _load_raw_file(const char *fn, xs_val **data, int *size, xs_str *_static_fn(snac *snac, const char *id) /* gets the filename for a static file */ { - if (strchr(id, '/')) + if (strstr(id, "..")) return NULL; else return xs_fmt("%s/static/%s", snac->basedir, id); @@ -5026,7 +5026,7 @@ int html_get_handler(const xs_dict *req, const char *q_path, } else if (xs_startswith(p_path, "s/")) { /** a static file **/ - xs *l = xs_split(p_path, "/"); + xs *l = xs_split_n(p_path, "/", 1); const char *id = xs_list_get(l, 1); int sz; |