Rework wikilinks feature
This commit is contained in:
@@ -96,9 +96,14 @@ func (h *handler) handleThumb(w http.ResponseWriter, r *http.Request) {
|
||||
http.Error(w, "bad path", http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
cleanPath := path.Clean(decoded)
|
||||
h.serveThumbnail(w, r, filepath.Join(h.root, filepath.FromSlash(path.Clean(decoded))))
|
||||
}
|
||||
|
||||
srcFS := filepath.Join(h.root, filepath.FromSlash(cleanPath))
|
||||
// serveThumbnail generates (or serves from cache) a thumbnail of the file at
|
||||
// srcFS, sized by the ?w= query. Both entry points land here: the /_thumb
|
||||
// route used by listings and the diary, and the ?w= query on a file's own URL,
|
||||
// which is the form embeds use so their <img src> stays relative to the page.
|
||||
func (h *handler) serveThumbnail(w http.ResponseWriter, r *http.Request, srcFS string) {
|
||||
rel, err := filepath.Rel(h.root, srcFS)
|
||||
if err != nil || strings.HasPrefix(rel, "..") {
|
||||
http.Error(w, "Forbidden", http.StatusForbidden)
|
||||
|
||||
Reference in New Issue
Block a user