Skip to content
Commit 75373b75 authored by Nick Thomas's avatar Nick Thomas Committed by John Jarvis
Browse files

Prevent a path traversal attack on global file templates

The API permits path traversal characters like '../' to be passed down
to the template finder. Detect these requests and cause them to fail
with a 500 response code.
parent c0ed50ba
Loading
Loading
Loading