mirror of https://github.com/go-gitea/gitea.git
From testing, I found that issue posters and users with repository write access are able to edit attachment names in a way that circumvents the instance-level file extension restrictions using the edit attachment APIs. This snapshot adds checks for these endpoints. |
4 months ago | |
---|---|---|
.. | ||
attachment.go | 4 months ago | |
attachment_test.go | 1 year ago |