Commit fca2104
committed
Avoid unsafe regex
In 321c465 (misc-helper: start implementing the Pipeline side of the new
strategy, 2018-12-19), I introduced a regular expression that could
potentially be used to DoS the GitGitGadget Pipelines runner, via a
crafted (and most likely invalid) slash command.
The saving grace here is that only users who are already allowed to use
GitGitGadget will even come as far with such a crafted command as to hit
that parser.
Nevertheless, it's better to be safe than to be sorry.
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>1 parent fd54c52 commit fca2104
1 file changed
+2
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
541 | 541 | | |
542 | 542 | | |
543 | 543 | | |
544 | | - | |
| 544 | + | |
545 | 545 | | |
546 | 546 | | |
547 | 547 | | |
548 | 548 | | |
549 | 549 | | |
550 | | - | |
| 550 | + | |
551 | 551 | | |
552 | 552 | | |
553 | 553 | | |
| |||
0 commit comments