0
0
mirror of https://github.com/go-gitea/gitea.git synced 2024-12-15 05:06:48 +01:00
gitea/services/context
Kemal Zebari 7adc4717ec
Include file extension checks in attachment API (#32151)
From testing, I found that issue posters and users with repository write
access are able to edit attachment names in a way that circumvents the
instance-level file extension restrictions using the edit attachment
APIs. This snapshot adds checks for these endpoints.
2024-11-06 21:34:32 +00:00
..
upload Include file extension checks in attachment API (#32151) 2024-11-06 21:34:32 +00:00
access_log.go
api_org.go
api_test.go
api.go Refactor RepoRefByType (#32413) 2024-11-05 06:35:54 +00:00
base_test.go
base.go
captcha.go
context_cookie.go
context_model.go
context_request.go
context_response.go
context_template.go
context_test.go
context.go Refactor template ctx and render utils (#32422) 2024-11-05 14:04:26 +08:00
csrf.go Refactor CSRF token (#32216) 2024-10-10 03:48:21 +00:00
org.go
package.go
pagination.go
permission.go Allow maintainers to view and edit files of private repos when "Allow maintainers to edit" is enabled (#32215) 2024-10-11 19:08:19 +00:00
private.go
repo.go Refactor RepoRefByType (#32413) 2024-11-05 06:35:54 +00:00
response.go
user.go
utils.go
xsrf_test.go
xsrf.go