aboutsummaryrefslogtreecommitdiffstats
path: root/routers/init.go
diff options
context:
space:
mode:
authorKemal Zebari <60799661+kemzeb@users.noreply.github.com>2024-11-06 13:34:32 -0800
committerGitHub <noreply@github.com>2024-11-06 21:34:32 +0000
commit7adc4717ec8e4f8fe678010866e936cf024f498d (patch)
tree5b16713339512a7d1ed75b8ee9747ed08975c590 /routers/init.go
parentf64fbd9b74998f3ac8353d2a8344e2e6f0ce1936 (diff)
downloadgitea-7adc4717ec8e4f8fe678010866e936cf024f498d.tar.gz
gitea-7adc4717ec8e4f8fe678010866e936cf024f498d.zip
Include file extension checks in attachment API (#32151)
From testing, I found that issue posters and users with repository write access are able to edit attachment names in a way that circumvents the instance-level file extension restrictions using the edit attachment APIs. This snapshot adds checks for these endpoints.
Diffstat (limited to 'routers/init.go')
0 files changed, 0 insertions, 0 deletions