Merge pull request #223 from gro-ove/master
Fixed: path traversal attack
This commit is contained in:
commit
a25b2fdadf
|
@ -1,3 +1,4 @@
|
||||||
|
var path = require("path");
|
||||||
var express = require("express");
|
var express = require("express");
|
||||||
var Config = require("./config");
|
var Config = require("./config");
|
||||||
var Logger = require("./logger");
|
var Logger = require("./logger");
|
||||||
|
@ -89,6 +90,11 @@ var Server = {
|
||||||
|
|
||||||
// default path
|
// default path
|
||||||
this.app.get("/:thing(*)", function (req, res, next) {
|
this.app.get("/:thing(*)", function (req, res, next) {
|
||||||
|
var root = __dirname + "/www/",
|
||||||
|
answer = path.resolve (__dirname + "/www/", req.params.thing);
|
||||||
|
if (answer.indexOf (root) != 0)
|
||||||
|
res.send (404);
|
||||||
|
else
|
||||||
res.sendfile(__dirname + "/www/" + req.params.thing);
|
res.sendfile(__dirname + "/www/" + req.params.thing);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue