Prevent directory traversal in UI Serving
Checking for directory base closes #5427
This commit is contained in:
		| @@ -109,6 +109,7 @@ def test_api_ui_fallback(botclient): | ||||
|     rc = client_get(client, "/something") | ||||
|     assert rc.status_code == 200 | ||||
|  | ||||
|     # Test directory traversal | ||||
|     rc = client_get(client, '%2F%2F%2Fetc/passwd') | ||||
|     assert rc.status_code == 200 | ||||
|     assert '`freqtrade install-ui`' in rc.text | ||||
|   | ||||
		Reference in New Issue
	
	Block a user