0
0
Fork 0
mirror of https://github.com/go-gitea/gitea synced 2024-12-25 12:04:50 +01:00
gitea/services/repository/files
sillyguodong 51ab495198
escape filename when assemble URL (#22850)
Fixes: #22843 

### Cause:

affdd40296/services/repository/files/content.go (L161)

Previously, we did not escape the **"%"** that might be in "treePath"
when call "url.parse()".


![image](https://user-images.githubusercontent.com/33891828/218066318-5a909e50-2a17-46e6-b32f-684b2aa4b91f.png)

This function will check whether "%" is the beginning of an escape
character. Obviously, the "%" in the example (hello%mother.txt) is not
that. So, the function will return a error.

### Solution:
We can escape "treePath" by call "url.PathEscape()" function firstly.

### Screenshot:

![image](https://user-images.githubusercontent.com/33891828/218069781-1a030f8b-18d0-4804-b0f8-73997849ef43.png)

---------

Signed-off-by: Andrew Thornton <art27@cantab.net>
Co-authored-by: Andrew Thornton <art27@cantab.net>
2023-02-12 09:31:14 +08:00
..
cherry_pick.go
commit.go
content.go escape filename when assemble URL (#22850) 2023-02-12 09:31:14 +08:00
content_test.go
delete.go
diff.go
diff_test.go
file.go
file_test.go
patch.go Refactor git command package to improve security and maintainability (#22678) 2023-02-04 10:30:43 +08:00
temp_repo.go Refactor git command package to improve security and maintainability (#22678) 2023-02-04 10:30:43 +08:00
tree.go
tree_test.go
update.go Refactor git command package to improve security and maintainability (#22678) 2023-02-04 10:30:43 +08:00
upload.go Refactor git command package to improve security and maintainability (#22678) 2023-02-04 10:30:43 +08:00