* Add short url validation
Path should not contain string ../
* Update pkg/api/short_url.go
Co-authored-by: Marcus Efraimsson <marcus.efraimsson@gmail.com>
Co-authored-by: Marcus Efraimsson <marcus.efraimsson@gmail.com>
(cherry picked from commit 7faea40674)
Co-authored-by: idafurjes <36131195+idafurjes@users.noreply.github.com>
This commit is contained in:
co-authored by
idafurjes
parent
33a7e11344
commit
f195dcc37a
@@ -23,6 +23,10 @@ func (hs *HTTPServer) createShortURL(c *models.ReqContext, cmd dtos.CreateShortU
|
||||
hs.log.Error("Invalid short URL path", "path", cmd.Path)
|
||||
return response.Error(400, "Path should be relative", nil)
|
||||
}
|
||||
if strings.Contains(cmd.Path, "../") {
|
||||
hs.log.Error("Invalid short URL path", "path", cmd.Path)
|
||||
return response.Error(400, "Invalid path", nil)
|
||||
}
|
||||
|
||||
shortURL, err := hs.ShortURLService.CreateShortURL(c.Req.Context(), c.SignedInUser, cmd.Path)
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user