Sanitized user-provided file names in HTTP multipart uploads

This commit is contained in:
pixeebot[bot] 2024-02-10 00:08:18 +00:00
parent 96e399a617
commit 68c0941666

View file

@ -75,7 +75,7 @@ public class ShowJavascript {
return WebResponseUtils.bytesToWebResponse(
script.getBytes(StandardCharsets.UTF_8),
inputFile.getOriginalFilename() + ".js");
Filenames.toSimpleFileName(inputFile.getOriginalFilename()) + ".js");
}
}
}