Skip to content

Confine transport.vfs.ReplyFileName header value to the configured VFS reply folder - #115

Open
ThisaraWeerakoon wants to merge 1 commit into
apache:masterfrom
ThisaraWeerakoon:f001
Open

ThisaraWeerakoon wants to merge 1 commit into
apache:masterfrom
ThisaraWeerakoon:f001

Conversation

@ThisaraWeerakoon

@ThisaraWeerakoon ThisaraWeerakoon commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Constrains the file name resolved from the transport.vfs.ReplyFileName transport header so it always resolves to a location within the configured VFS reply folder, rejecting values that would resolve elsewhere.

…fine it to, the configured VFS reply folder.
@ThisaraWeerakoon ThisaraWeerakoon changed the title Fix Confine transport.vfs.ReplyFileName header value to the configured VFS reply folder Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant