need to untaint..

master
Joey Hess 2008-07-21 16:20:02 -04:00
parent 2461ce0de6
commit b182f5e573
1 changed files with 6 additions and 1 deletions

View File

@ -135,7 +135,12 @@ sub sessioncgi ($$) { #{{{
elsif (! -f "$config{srcdir}/$file") {
error(sprintf(gettext("%s is not a file"), $file));
}
push @files, $file;
# This untaint is safe because we've
# verified the file is a known source file,
# and is in the srcdir, and is a regular
# file.
push @files, possibly_foolish_untaint($file);
}
# Do removal, and update the wiki.