diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Require a boundary in the about-path prefix check
The about subpath was confined to the readme directory with a plain
byte-prefix match, so a sibling directory sharing the base name as a
prefix passed the check and its files were served.
| -rw-r--r-- | source/ui-summary.c | 8 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 7 insertions, 1 deletion
diff --git a/source/ui-summary.c b/source/ui-summary.c index 471f0c9..a5f3ae8 100644 --- a/source/ui-summary.c +++ b/source/ui-summary.c @@ -86,7 +86,13 @@ static char* append_readme_path(const char *filename, const char *ref, const cha if (!ref) { resolved_base = realpath(base_dir, NULL); resolved_full = realpath(full_path, NULL); - if (!resolved_base || !resolved_full || !starts_with(resolved_full, resolved_base)) { + /* Require a path-separator boundary after the base so a sibling + * directory that merely shares the base as a name prefix (say + * repo.git-backup next to repo.git) cannot pass the check. */ + if (!resolved_base || !resolved_full || + !starts_with(resolved_full, resolved_base) || + (resolved_full[strlen(resolved_base)] != '\0' && + resolved_full[strlen(resolved_base)] != '/')) { free(full_path); full_path = NULL; } |
