Skip to content

Commit 502c8a0

Browse files
author
catlog22
committed
fix(security): Apply 3 critical security fixes
- sec-001: Add validateAllowedPath to /api/file endpoint (path traversal) - sec-002: Enable CSRF by default with CCW_DISABLE_CSRF opt-out - sec-003: Add validateAllowedPath to /api/dialog/browse and /api/dialog/open-file (path traversal) Ref: fix-1738072800000
1 parent ed0255b commit 502c8a0

5 files changed

Lines changed: 808 additions & 4 deletions

File tree

0 commit comments

Comments
 (0)