fix(10.1-04): refuse percent-encoded dot segments in plugin asset URLs

The URL parser resolves %2e%2e like .., so /{base}/assets/%2e%2e/api/...
passed assetAllowed and would load from outside the asset prefix. A
segment is now a dot segment after decoding %2e, in any case.

- tests/app/pluginAssets.test.ts covers the URL check, loadScript,
  loadStyles, activateStyles and loadControllerAssets
- modules/boardwalk/dist rebuilt
This commit is contained in:
Jakub Zych
2026-09-29 02:52:14 +02:00
parent 7eed4acd87
commit 6b0ac15086
4 changed files with 211 additions and 4 deletions

File diff suppressed because one or more lines are too long

View File

@@ -6,7 +6,7 @@
<meta name="robots" content="noindex, nofollow" />
<meta name="summer-admin-base" content="__SUMMER_ADMIN_BASE__" />
<title>SummerCMS</title>
<script type="module" crossorigin src="./assets/index-DMFEtOWd.js"></script>
<script type="module" crossorigin src="./assets/index-B51qJou6.js"></script>
<link rel="stylesheet" crossorigin href="./assets/index-CfeX_snf.css">
</head>
<body>