static.File shouldn't allow excessive /s.
|Reported by:||jknight||Owned by:|
Using static.File('/'), I can successfully get the contents of /etc/resolv.conf with the url http://localhost:8080/etc//////resolv.conf////. There's two things wrong with this:
- Empty segments. Either that should be an error or a redirect.
- a / after a file (not a directory) should surely be an error.
Change History (11)
comment:4 in reply to: ↑ 2 Changed 8 years ago by jknight
- Cc jknight added
- Milestone set to Web2-Gold-Master
- Priority changed from highest to high
comment:10 Changed 3 years ago by exarkun
- Resolution set to wontfix
- Status changed from new to closed
Note: See TracTickets for help on using tickets.