diff options
| author | Fuwn <[email protected]> | 2026-04-18 08:55:09 +0000 |
|---|---|---|
| committer | Fuwn <[email protected]> | 2026-04-18 08:55:09 +0000 |
| commit | d7d7a5f00be218540b98e4a923606cf57bbd23e9 (patch) | |
| tree | 3088bb7b6fd844e3ba5b139b91090506af057132 /static/aobuta | |
| parent | fix(utility): treat .localhost subdomains as private in appOrigin (diff) | |
| download | due.moe-d7d7a5f00be218540b98e4a923606cf57bbd23e9.tar.xz due.moe-d7d7a5f00be218540b98e4a923606cf57bbd23e9.zip | |
fix(api): encode subsplease timezone to prevent query-param injection
The `tz` query value was interpolated raw into the upstream URL, letting
callers append arbitrary query segments (e.g. `tz=foo&f=hax`). Wrap the
value in encodeURIComponent and rename the local variable away from the
banned `tz` abbreviation.
Diffstat (limited to 'static/aobuta')
0 files changed, 0 insertions, 0 deletions