mirror of
https://gitcode.com/gitea/gitea.git
synced 2025-12-03 21:18:27 +08:00
From testing, I found that issue posters and users with repository write access are able to edit attachment names in a way that circumvents the instance-level file extension restrictions using the edit attachment APIs. This snapshot adds checks for these endpoints.
1.5 KiB
1.5 KiB