sanitize path from URL

pull/290/head
Fabian Jakobs 2016-04-11 09:08:51 +00:00
rodzic 1fc4db9e84
commit d720d7365a
1 zmienionych plików z 1 dodań i 1 usunięć

Wyświetl plik

@ -176,7 +176,7 @@ function plugin(options, imports, register) {
api.get("/update/:path*", function(req, res, next) {
var filename = req.params.path;
var path = resolve(__dirname + "/../../build/output/" + filename);
var path = resolve(__dirname + "/../../build/output/" + resolve("/" + filename));
var stream = fs.createReadStream(path);
stream.on("error", function(err) {