From a794440b8fbed43dcd0f6a60d3557a43fe8c1cac Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 16 Jul 2026 08:47:57 -1000 Subject: Require a boundary in the about-path prefix check The about subpath was confined to the readme directory with a plain byte-prefix match, so a sibling directory sharing the base name as a prefix passed the check and its files were served. --- source/ui-summary.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'source/ui-summary.c') diff --git a/source/ui-summary.c b/source/ui-summary.c index 471f0c9..a5f3ae8 100644 --- a/source/ui-summary.c +++ b/source/ui-summary.c @@ -86,7 +86,13 @@ static char* append_readme_path(const char *filename, const char *ref, const cha if (!ref) { resolved_base = realpath(base_dir, NULL); resolved_full = realpath(full_path, NULL); - if (!resolved_base || !resolved_full || !starts_with(resolved_full, resolved_base)) { + /* Require a path-separator boundary after the base so a sibling + * directory that merely shares the base as a name prefix (say + * repo.git-backup next to repo.git) cannot pass the check. */ + if (!resolved_base || !resolved_full || + !starts_with(resolved_full, resolved_base) || + (resolved_full[strlen(resolved_base)] != '\0' && + resolved_full[strlen(resolved_base)] != '/')) { free(full_path); full_path = NULL; } -- cgit v2.8.0