This commit is contained in:
2026-01-17 12:07:59 +08:00
parent e12908f54f
commit dec540d055
3 changed files with 6 additions and 3 deletions

View File

@@ -8,7 +8,7 @@
*/
export const validateDirectory = (directory?: string) => {
// 对directory进行校验不能以/开头,不能以/结尾。不能以.开头,不能以.结尾。
if (directory && (directory.startsWith('/') || directory.endsWith('/') || directory.startsWith('.') || directory.endsWith('.'))) {
if (directory && (directory.startsWith('/') || directory.endsWith('/') || directory.startsWith('..') || directory.endsWith('..'))) {
return {
code: 500,
message: 'directory is invalid',