Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A simpler fix might be to canonicalize (i.e. no "..") the public folder path and the requested file path and then ensure the public path is a prefix of the other.


Any fix also needs to be sure to resolve any symlinks before doing a prefix check.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: