csrf token handling, two jwt tokens
This commit is contained in:
@@ -392,7 +392,8 @@ router.get('/images/:filename',
|
||||
helmet.crossOriginResourcePolicy({ policy: "cross-origin" }),
|
||||
async (req, res) => {
|
||||
try {
|
||||
const { filename } = req.params;
|
||||
// Sanitize filename to prevent path traversal attacks
|
||||
const filename = path.basename(req.params.filename);
|
||||
|
||||
// Verify user is sender or receiver of a message with this image
|
||||
const message = await Message.findOne({
|
||||
|
||||
Reference in New Issue
Block a user