Skip to content

Conversation

@rameel
Copy link
Owner

@rameel rameel commented Aug 14, 2025

Previously, only full file paths were matched against glob patterns, allowing unintended directories to be enumerated.

Now folder paths are properly validated against the patterns (e.g. /assets/{images,styles}/**/*.{png,gif,css}) correctly restricts access to only allowed paths.

rameel added 5 commits August 14, 2025 04:54
…rectly

Previously, only full file paths were matched against glob patterns, allowing unintended directories to be enumerated. Now folder paths are properly validated against the patterns (e.g. `/assets/{images,styles}/**/*.{png,gif,css}` correctly restricts access to only allowed paths).
@rameel rameel merged commit ddb4770 into main Aug 14, 2025
2 checks passed
@rameel rameel deleted the globbing-provider branch August 14, 2025 00:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants