Skip to content

WIP: Endpoint() constructor: Roundtrip the URL through URIs.resolvereference(), and make sure it is unchanged #53

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Draft
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

DilumAluthge
Copy link
Member

@DilumAluthge DilumAluthge commented Jun 21, 2025

This serves as an additional sanity check that the endpoint URL doesn't contain any path traversal.

On its own, I don't think this is sufficient, so I think we should still keep the existing checks.

@DilumAluthge DilumAluthge force-pushed the dpa/resolvereference branch 2 times, most recently from 3823787 to 77282c6 Compare June 21, 2025 01:52
@DilumAluthge DilumAluthge force-pushed the dpa/resolvereference branch from 1bd86c8 to 8072388 Compare June 21, 2025 02:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant