mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-08 03:08:02 +00:00
fix: exclude query/fragment delimiters from user-ID regex segment
Change [^/]+ to [^/?#]+ so that inputs like /api/v1/users/alice?x=1/profile/image are rejected — the browser would interpret ? as the query string start, making the actual request target /api/v1/users/alice instead of the intended route.
This commit is contained in:
parent
a8f7b743ff
commit
3da3b6b929
1 changed files with 3 additions and 3 deletions
|
|
@ -3,10 +3,10 @@
|
|||
import re
|
||||
from urllib.parse import urlparse
|
||||
|
||||
# Matches the OWUI-generated profile image route. The ``[^/]+`` segment
|
||||
# accepts any user-ID without allowing path-traversal across segments,
|
||||
# Matches the OWUI-generated profile image route. ``[^/?#]+`` accepts
|
||||
# any user-ID without allowing path-traversal or query/fragment injection,
|
||||
# and the ``$`` anchor rejects trailing path components.
|
||||
_USER_PROFILE_IMAGE_RE = re.compile(r'^/api/v1/users/[^/]+/profile/image$')
|
||||
_USER_PROFILE_IMAGE_RE = re.compile(r'^/api/v1/users/[^/?#]+/profile/image$')
|
||||
|
||||
# Validates MIME type and structure of base64 data URIs. Only the prefix
|
||||
# is checked — validating the full base64 payload would mean running a
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue