Skip to content

Commit

Permalink
Added security check.
Browse files Browse the repository at this point in the history
  • Loading branch information
bartkamphorst committed Sep 20, 2015
1 parent 288f759 commit ce68a88
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions lib/gollum/app.rb
Original file line number Diff line number Diff line change
Expand Up @@ -176,6 +176,7 @@ def wiki_new
fullname = params[:file][:filename]
tempfile = params[:file][:tempfile]
end
halt 500 unless tempfile.is_a? Tempfile

# Remove page file dir prefix from upload path if necessary -- committer handles this itself
dir = wiki.per_page_uploads ? params[:upload_dest].match(/^(#{wiki.page_file_dir}\/+)?(.*)/)[2] : 'uploads'
Expand Down

0 comments on commit ce68a88

Please sign in to comment.