aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorla_ninpre <aaoth@aaoth.xyz>2026-01-28 11:30:03 +0300
committerla_ninpre <aaoth@aaoth.xyz>2026-01-28 11:39:44 +0300
commit2f0f3d45f4335327c269a689fbeb62b3003695aa (patch)
tree4a6f455e33572e1f58beefc4a03efcaccf89408e
parentf7073bfe61c6e011ec861edd07c791c884b6ff45 (diff)
static files: allow files in a subdirectory
allowing '/' in paths is a bit scary, but replacing the check with reject on '..' seems to work. please correct me if i'm wrong and this is insecure.
-rw-r--r--data.c2
-rw-r--r--html.c2
2 files changed, 2 insertions, 2 deletions
diff --git a/data.c b/data.c
index 27825ad..02686e1 100644
--- a/data.c
+++ b/data.c
@@ -2691,7 +2691,7 @@ static int _load_raw_file(const char *fn, xs_val **data, int *size,
xs_str *_static_fn(snac *snac, const char *id)
/* gets the filename for a static file */
{
- if (strchr(id, '/'))
+ if (strstr(id, ".."))
return NULL;
else
return xs_fmt("%s/static/%s", snac->basedir, id);
diff --git a/html.c b/html.c
index 7b93e49..2a03579 100644
--- a/html.c
+++ b/html.c
@@ -5026,7 +5026,7 @@ int html_get_handler(const xs_dict *req, const char *q_path,
}
else
if (xs_startswith(p_path, "s/")) { /** a static file **/
- xs *l = xs_split(p_path, "/");
+ xs *l = xs_split_n(p_path, "/", 1);
const char *id = xs_list_get(l, 1);
int sz;