浏览代码

fix: disallow # char in file uploads (#3770)

opalmay 4 年之前
父节点
当前提交
9081232e7c
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      server/controllers/upload.js

+ 1 - 1
server/controllers/upload.js

@@ -76,7 +76,7 @@ router.post('/u', (req, res, next) => {
   }
 
   // Sanitize filename
-  fileMeta.originalname = sanitize(fileMeta.originalname.toLowerCase().replace(/[\s,;]+/g, '_'))
+  fileMeta.originalname = sanitize(fileMeta.originalname.toLowerCase().replace(/[\s,;#]+/g, '_'))
 
   // Check if user can upload at path
   const assetPath = (folderId) ? hierarchy.map(h => h.slug).join('/') + `/${fileMeta.originalname}` : fileMeta.originalname