fix: prevent upload bypass via uppercase path
This commit is contained in:
		| @@ -32,7 +32,7 @@ module.exports = { | |||||||
|         token = req.cookies['jwt'] |         token = req.cookies['jwt'] | ||||||
|       } |       } | ||||||
|       // Force uploads to use Auth headers |       // Force uploads to use Auth headers | ||||||
|       if (req.path === '/u') { |       if (req.path.toLowerCase() === '/u') { | ||||||
|         return null |         return null | ||||||
|       } |       } | ||||||
|       return token |       return token | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user