Closed EsadCetiner closed 3 months ago
@EsadCetiner How are you enforing that this exclusion is used only for static files?
@azurit I'm not, the variable is only used for static files. Do you want me to write another rule that makes that check?
@EsadCetiner I would better do it. I suggest to restrict it based on file extension.
@azurit everything good to merge now?
Fixes false positives when requesting a static file at pl-2 or higher with the ver argument. I haven't done any character whitelisting since this is just used for static files, there's nothing to attack.