fix: prevent upload bypass via uppercase path

This commit is contained in:
Nicolas Giard
2022-01-29 18:45:51 -05:00
committed by GitHub
parent cab16ee844
commit 7b14b39de0

View File

@@ -32,7 +32,7 @@ module.exports = {
token = req.cookies['jwt'] token = req.cookies['jwt']
} }
// Force uploads to use Auth headers // Force uploads to use Auth headers
if (req.path === '/u') { if (req.path.toLowerCase() === '/u') {
return null return null
} }
return token return token