Glucksberg
34e2425b4d
fix(security): restrict MEDIA path extraction to prevent LFI ( #4930 )
...
* fix(security): restrict inbound media staging to media directory
* docs: update MEDIA path guidance for security restrictions
- Update agent hint to warn against absolute/~ paths
- Update docs example to use https:// instead of /tmp/
---------
Co-authored-by: Evan Otero <evanotero@google.com>
2026-01-31 10:55:37 -08:00
..
2026-01-30 03:16:21 +01:00
2026-01-29 23:37:32 -05:00
2026-01-31 22:46:19 +05:30
2026-01-31 22:46:19 +05:30
2026-01-31 21:13:13 +09:00
2026-01-31 15:50:15 +01:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 15:50:15 +01:00
2026-01-31 21:13:13 +09:00
2026-01-30 03:16:21 +01:00
2026-01-10 20:05:22 +01:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 10:55:37 -08:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-30 03:16:21 +01:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-30 03:16:21 +01:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 15:55:59 +01:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 04:20:12 +01:00
2026-01-31 15:50:15 +01:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-31 21:13:13 +09:00
2026-01-30 03:16:21 +01:00