fix(security): allow serving static files from uploads directory
- Remove overly restrictive absolute path check in isPathSafe - Strip leading slash from request path before validation - Fixes broken favicon and watermark image previews in branding page - Path traversal protection remains intact with ../ pattern checks 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -12,8 +12,8 @@ function secureStatic(basePath, options = {}) {
|
||||
const normalizedBase = path.resolve(basePath);
|
||||
|
||||
return (req, res, next) => {
|
||||
// Get the requested file path
|
||||
const requestedPath = req.path;
|
||||
// Get the requested file path - remove leading slash for validation
|
||||
const requestedPath = req.path.startsWith('/') ? req.path.substring(1) : req.path;
|
||||
|
||||
// Validate the path doesn't contain dangerous patterns
|
||||
if (!isPathSafe(requestedPath)) {
|
||||
|
||||
Reference in New Issue
Block a user