Browse Source

Sanitize upload filename like URL

bel2125 4 years ago
parent
commit
b2ed60c589
1 changed files with 2 additions and 0 deletions
  1. 2 0
      src/handle_form.inl

+ 2 - 0
src/handle_form.inl

@@ -55,6 +55,8 @@ url_encoded_field_found(const struct mg_connection *conn,
 			mg_cry_internal(conn, "%s: Cannot decode filename", __func__);
 			mg_cry_internal(conn, "%s: Cannot decode filename", __func__);
 			return MG_FORM_FIELD_STORAGE_SKIP;
 			return MG_FORM_FIELD_STORAGE_SKIP;
 		}
 		}
+		remove_dot_segments(filename_dec);
+
 	} else {
 	} else {
 		filename_dec[0] = 0;
 		filename_dec[0] = 0;
 	}
 	}