comparison rewrite-log @ 1825:a9343f9d7365

Make hgweb.staticfile() more secure and portable. Without this, files in directories next to the static directory starting with 'static' could be retrieved, e.g. with '../static.private/foo'. Additionally staticfile now generates platform specific pathnames from the /-separated paths given in the URL. Illegal file names (e.g. containing %00) now yield a sane error message.
author Thomas Arendsen Hein <thomas@intevation.de>
date Thu, 02 Mar 2006 09:17:04 +0100
parents 5f471a75d607
children
comparison
equal deleted inserted replaced
1824:dca000ef7d52 1825:a9343f9d7365