fix(10.1-04): refuse percent-encoded dot segments in plugin asset URLs
The URL parser resolves %2e%2e like .., so /{base}/assets/%2e%2e/api/...
passed assetAllowed and would load from outside the asset prefix. A
segment is now a dot segment after decoding %2e, in any case.
- tests/app/pluginAssets.test.ts covers the URL check, loadScript,
loadStyles, activateStyles and loadControllerAssets
- modules/boardwalk/dist rebuilt
This commit is contained in:
File diff suppressed because one or more lines are too long
2
modules/boardwalk/dist/index.html
vendored
2
modules/boardwalk/dist/index.html
vendored
@@ -6,7 +6,7 @@
|
||||
<meta name="robots" content="noindex, nofollow" />
|
||||
<meta name="summer-admin-base" content="__SUMMER_ADMIN_BASE__" />
|
||||
<title>SummerCMS</title>
|
||||
<script type="module" crossorigin src="./assets/index-DMFEtOWd.js"></script>
|
||||
<script type="module" crossorigin src="./assets/index-B51qJou6.js"></script>
|
||||
<link rel="stylesheet" crossorigin href="./assets/index-CfeX_snf.css">
|
||||
</head>
|
||||
<body>
|
||||
|
||||
Reference in New Issue
Block a user