Changeset 92:855f32e97b48 in iovar


Ignore:
Timestamp:
Feb 28, 2017, 7:12:45 AM (20 months ago)
Author:
Shawn Wilson <shawn@…>
Branch:
default
Phase:
public
Message:

comment on previous change

File:
1 edited

Legend:

Unmodified
Added
Removed
  • src/win/iovar/web/Default.java

    r91 r92  
    387387                Log.debug ("getResource () -- found symbolic link");
    388388                fpath = Files.readSymbolicLink (fpath);
     389               
     390                /* SECURITY: making link relative to project root (prevent sandbox escape) -- re-evaluate if needed */
    389391                target = new File (base, fpath.toString ()).getCanonicalFile ();
    390392                Log.debug ("getResource () link target: "+target);
Note: See TracChangeset for help on using the changeset viewer.