maziggy
4d94286e53
Fix CodeQL path injection vulnerabilities
- projects.py: Add path traversal validation to attachment endpoints
- Reject filenames containing /, \, or ..
- Prevents directory traversal attacks via URL parameters
- archives.py: Strengthen timelapse processing input validation
- Validate audio suffix against whitelist (not just filename check)
- Reject output filenames with .., empty, or dot-prefixed names
- Fall back to safe default filename if validation fails
2026-02-05 18:09:42 +01:00
..
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-05 18:09:42 +01:00
2026-01-31 12:50:15 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-01-31 12:50:15 +01:00
2026-02-03 09:13:00 +01:00
2026-02-05 17:30:14 +01:00
2026-02-03 09:13:00 +01:00
2026-02-04 07:20:17 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-05 07:46:22 +01:00
2026-02-05 17:50:16 +01:00
2026-02-05 17:30:14 +01:00
2026-02-05 18:09:42 +01:00
2026-02-04 12:29:20 +01:00
2026-02-03 09:13:13 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 13:02:36 +01:00
2026-02-03 09:13:00 +01:00
2026-02-03 09:13:00 +01:00
2026-02-01 11:29:17 +01:00
2026-01-19 13:29:37 +01:00
2026-01-12 15:15:53 +01:00