refac
This commit is contained in:
@@ -31,14 +31,20 @@ def _sanitize_proxy_path(path: str) -> str | None:
|
||||
"""Sanitize a proxy path to prevent directory traversal / SSRF.
|
||||
|
||||
Returns the cleaned path, or None if the path is invalid.
|
||||
Trailing slashes are preserved — many upstream frameworks treat
|
||||
``/path`` and ``/path/`` differently.
|
||||
"""
|
||||
decoded = unquote(path)
|
||||
had_trailing_slash = decoded.endswith('/')
|
||||
normalized = posixpath.normpath(decoded)
|
||||
# Remove any leading slashes that would reset the base
|
||||
cleaned = normalized.lstrip('/')
|
||||
# Reject if normpath resolved to parent traversal or current-dir only
|
||||
if cleaned.startswith('..') or cleaned == '.':
|
||||
return None
|
||||
# Restore trailing slash if the original path had one
|
||||
if had_trailing_slash and cleaned and not cleaned.endswith('/'):
|
||||
cleaned += '/'
|
||||
return cleaned
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user