Skip to content

Commit 03af18f

Browse files
committed
fix: validate resource file paths in ui middleware
1 parent cb8022a commit 03af18f

1 file changed

Lines changed: 10 additions & 1 deletion

File tree

‎internal/middleware/ui_middleware.go‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ import (
44
"io/fs"
55
"net/http"
66
"os"
7+
"path/filepath"
78
"strings"
89
"tinyauth/internal/assets"
910

@@ -52,7 +53,15 @@ func (m *UIMiddleware) Middleware() gin.HandlerFunc {
5253
c.Next()
5354
return
5455
case "resources":
55-
_, err := os.Stat(m.Config.ResourcesDir + strings.TrimPrefix(c.Request.URL.Path, "/resources/"))
56+
requestFilePath := m.Config.ResourcesDir + strings.TrimPrefix(c.Request.URL.Path, "/resources/")
57+
58+
if !filepath.IsLocal(requestFilePath) {
59+
c.Status(404)
60+
c.Abort()
61+
return
62+
}
63+
64+
_, err := os.Stat(requestFilePath)
5665

5766
if os.IsNotExist(err) {
5867
c.Status(404)

0 commit comments

Comments
 (0)