692ab6835f
- only accept ASCII-encoded .dirindex files (this is guaranteed to work fine "everywhere"); - reject .dirindex files with a 'path' entry that contains a backslash or starts with a slash; - reject .dirindex files with a 'path' entry that contains a '..' component; - reject .dirindex files with an 'f', 'd' or 't' entry whose name field contains a slash or a backslash; - reject .dirindex files with an 'f', 'd' or 't' entry whose name field is '..'; - add comment lines (starting with '#') in the sample good .dirindex file used by unit tests. |
||
---|---|---|
.. | ||
bad | ||
good |