mirror of
https://github.com/harttle/liquidjs.git
synced 2026-09-29 07:05:13 -07:00
docs: path traversal vulnerabilities when customizing FS
This commit is contained in:
@@ -88,6 +88,9 @@ var engine = new Liquid({
|
|||||||
exists () {
|
exists () {
|
||||||
return true
|
return true
|
||||||
},
|
},
|
||||||
|
contains () {
|
||||||
|
return true
|
||||||
|
},
|
||||||
resolve(root, file, ext) {
|
resolve(root, file, ext) {
|
||||||
return file
|
return file
|
||||||
}
|
}
|
||||||
@@ -95,6 +98,8 @@ var engine = new Liquid({
|
|||||||
});
|
});
|
||||||
```
|
```
|
||||||
|
|
||||||
|
{% note warn Path Traversal Vulnerability %}The default value of <code>contains()</code> always returns true. That means when specifying an abstract file system, you'll need to provide a proper <code>contains()</code> to avoid expose such vulnerabilities.{% endnote %}
|
||||||
|
|
||||||
[fs]: ../api/interfaces/liquid_options_.liquidoptions.html#Optional-fs
|
[fs]: ../api/interfaces/liquid_options_.liquidoptions.html#Optional-fs
|
||||||
[ifs]: https://github.com/harttle/liquidjs/blob/master/src/fs/ifs.ts
|
[ifs]: https://github.com/harttle/liquidjs/blob/master/src/fs/ifs.ts
|
||||||
[fs-node]: https://github.com/harttle/liquidjs/blob/master/src/fs/node.ts
|
[fs-node]: https://github.com/harttle/liquidjs/blob/master/src/fs/node.ts
|
||||||
|
|||||||
+1
-1
@@ -9,7 +9,7 @@ export interface FS {
|
|||||||
readFileSync: (filepath: string) => string;
|
readFileSync: (filepath: string) => string;
|
||||||
/** resolve a file against directory, for given `ext` option */
|
/** resolve a file against directory, for given `ext` option */
|
||||||
resolve: (dir: string, file: string, ext: string) => string;
|
resolve: (dir: string, file: string, ext: string) => string;
|
||||||
/** check if file is contained in `root`, always return `true` by default */
|
/** check if file is contained in `root`, always return `true` by default. Warning: not setting this could expose path traversal vulnerabilities. */
|
||||||
contains?: (root: string, file: string) => boolean;
|
contains?: (root: string, file: string) => boolean;
|
||||||
/** defaults to "/" */
|
/** defaults to "/" */
|
||||||
sep?: string;
|
sep?: string;
|
||||||
|
|||||||
Reference in New Issue
Block a user