eggjs / egg-security

Security plugin for egg, force performance too.
MIT License
238 stars 43 forks source link

fix: absolute path detect should ignore evil path #29

Closed fengmk2 closed 6 years ago

fengmk2 commented 6 years ago

pick from https://github.com/eggjs/egg-security/pull/28

codecov[bot] commented 6 years ago

Codecov Report

Merging #29 into 1.x will not change coverage. The diff coverage is 100%.

Impacted file tree graph

@@           Coverage Diff           @@
##              1.x      #29   +/-   ##
=======================================
  Coverage   95.89%   95.89%           
=======================================
  Files          26       26           
  Lines         438      438           
=======================================
  Hits          420      420           
  Misses         18       18
Impacted Files Coverage Δ
lib/helper/shtml.js 94.73% <ø> (ø) :arrow_up:
lib/safe_redirect.js 100% <100%> (ø) :arrow_up:

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update 3fa64e1...01df37b. Read the comment docs.

jtyjty99999 commented 6 years ago

rebase?

fengmk2 commented 6 years ago

@jtyjty99999 我发版本。

fengmk2 commented 6 years ago

1.12.2