From bc5b6dfb6363f588d2e8ad0291ea7f91100ad7a7 Mon Sep 17 00:00:00 2001 From: Damien Elmes Date: Sat, 11 Jul 2020 10:53:41 +1000 Subject: [PATCH] mediasrv symlink fix https://forums.ankiweb.net/t/anki-2-1-28-beta/629/39 --- qt/aqt/mediasrv.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/qt/aqt/mediasrv.py b/qt/aqt/mediasrv.py index 5e4f7b83a..3d22e3fae 100644 --- a/qt/aqt/mediasrv.py +++ b/qt/aqt/mediasrv.py @@ -105,7 +105,7 @@ def allroutes(pathin): directory = os.path.realpath(directory) path = os.path.normpath(path) - fullpath = os.path.realpath(os.path.join(directory, path)) + fullpath = os.path.abspath(os.path.join(directory, path)) # protect against directory transversal: https://security.openstack.org/guidelines/dg_using-file-paths.html if not fullpath.startswith(directory):