Skip to content
Snippets Groups Projects

Input validation

What does this mr do?

The file names which were passed as parameters weren't filtered. Closes: #624, #625.

Actions taken to fix bug

The methods which take said file names as parameters, now strip the '../' sequences from them, preventing access to unauthorized directories.

Does this MR meet the acceptance criteria?

  • I have added a changelog entry to reflect the significant changes I made and the bug I fixed.
  • A test was created to test the bug.
  • I have updated the documentation accordingly.
  • I adhere to the style guide.
Edited by Marina Mădăraş

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
Please register or sign in to reply
Loading