Oliver Simmons oliversimmo at gmail.com
Sat May 15 14:11:58 BST 2021
- - - - - - - - - - - - - - - - - - -
On Sat, 15 May 2021 at 12:09, Almaember <almaember at disroot.org> wrote:
A question to everybody reading the list, how badly would it break the
spec to simply block any request whose URLs contain ".." as a standalone
path-element?
I don't think it would break anything, seems perfectly logical to meto block `..` as a part of a path.Blocking `~` and `.` as well would be good.
-Oliver Simmons