Closed ben-xo closed 2 years ago
This version should show a 404 if ?dir= is an arbitrary path, rather than leaking information about what's on the server. Also adds some tests which were missing around this functionality.
This is now merged.
This version should show a 404 if ?dir= is an arbitrary path, rather than leaking information about what's on the server. Also adds some tests which were missing around this functionality.