From b2c1e7e305b53190d55514658eca10c0718bf3f3 Mon Sep 17 00:00:00 2001 From: bohung Date: Tue, 1 Nov 2022 21:06:02 +0800 Subject: [PATCH] Fix vulnerable. --- app/controllers/archives_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/archives_controller.rb b/app/controllers/archives_controller.rb index 7a0d6a5..7e84fe1 100644 --- a/app/controllers/archives_controller.rb +++ b/app/controllers/archives_controller.rb @@ -7,7 +7,7 @@ class ArchivesController < ApplicationController def serve_cmap file_name = File.basename(params[:file_name].to_s) extension = File.basename(params[:extension].to_s) - serve_path=File.expand_path("../../assets/javascripts/archive/pdf/bcmaps/#{file_name}.#{extension}",__FILE__) + serve_path = File.expand_path("../../assets/javascripts/archive/pdf/bcmaps/#{file_name}.#{extension}",__FILE__) if Dir.glob(serve_path).length != 0 send_file(serve_path, type: "application/octet-stream") else